8 ms·
Researchers discovered the perfect password that’s easy to remember
- ChuckMcM 11y agoAnd if we could only get password taking software to not require special characters and numbers if the password was longer than 15 characters, life would be peachy. (that is 19 characters if you're wondering, and no I don't use it as a password)
- morganvachon 11y agoMy biggest pet peeve with password requirements is limiting the scope of special characters to some arbitrary subset, i.e. "you may only use the characters @#$%^& in your password", or not allowing spaces. Without spaces I can't use a phrase without running it all together, and my instinct is to type the spaces, so I end up getting frustrated and using some less secure password instead.
- fredcy 11y agoJust this week I found that Wordpress cannot handle passwords with ' or " because of bogus "escaping" posted data.
- chrisfarms 11y agoWhenever I see those sorts of limitation I assume there's probably some kind of poorly handled escape situation to exploit and their fix was "well just don't allow that pesky < character"
- JoshTriplett 11y ago> Whenever I see those sorts of limitation I assume there's probably some kind of poorly handled escape situation to exploit Which, in turn, implies that some system handles the password as plaintext rather than via a password-appropriate digest.
- aero142 11y agoWhich is why I use the method of making up a random sentence with a number in it and using the first letters of each word and the punctuation. I memorize the sentence. My favorite 7 beavers aren't taking to water! Password would be: Mf7ba'ttw! It's highly random just like the poems. It's easier for me to remember. It has the right length and random symbols to make the strong password detectors happy. You tend to say the sentence as you type the password so for bonus points, you can make it a nice motivational mantra. You're good enough, you're smart enough, and doggone it, people like you. Y'ge,y'se,adi,ply.
- vagelim 11y agoWhy use the abbreviation instead of the full sentence?
- aero142 11y agoThe original complain was about password boxes not allowing passwords longer than 15 characters. Another common complain is only a few special characters allowed and space is often not on the allowed list. This gets you most of the memorability while still working with the common password box restrictions.
- kristopolous 11y agoI've built up partial evidence that as the rules become more restrictive, the triviality of the password INCREASES and the entropy DECREASES. The idea is that people can't use their personal passwords so they fall back on trivial variations of common ones. For evidence, I've been assembling so called "cracks" and database "leaks" over the past several years and cataloging the password policies on the sites and then doing statistical analysis on the passwords. It's in interesting project ... check my user info and email me if you want to know more about this
- ColinDabritz 11y agoUsing rhyme and meter to remember things has a rich history, back to the epic poems. The phrasing of the title made me think of an Onion article along the lines of: They found the perfect password, it's '42Lemons?' and everyone should use it! What they found is an excellent password scheme for humans.
- thaumasiotes 11y ago> The phrasing of the title made me think of an Onion article along the lines of: They found the perfect password, it's '42Lemons?' and everyone should use it! I thought the same thing. A great example of "what worked for someone else may not work for you".
- codemac 11y agoAll passwords should not be memorable. Once you see them as tokens that 3rd parties will probably lose, then you know our efforts should be in secure token management software (keepass, lastpass, 1password, etc).
- bradleyjg 11y agoIf they aren't memorable then they are something you have, not something you know. Now you are down to one factor. To put it another way, what would you suggest for a master password for the token management software?
- DannoHung 11y agoMaybe the problem is that we have it backwards. Maybe it shouldn't be something you remember and push to the authentication mechanism, but something that the authentication mechanism pushes to you. Like, what if you pick the corpus of a novel that you've read as your master password. And the password manager uses that novel plus several other novels that you have selected (but didn't read/won't read?) to give you a series of multiple choice selections to determine if you know the right book. Just a few short passages. Preferably with proper nouns stripped out. You have to select the passages from the correct book for all the multiple choices. That way rather than recall, the memory factor is recognition. Combine it with a non-memorable token which you have to present first in order to even see the recognition factor test and you might have something workable.
- dangerlibrary 11y agoThe entropy of multiple choice selections is easily calculable and very low. number of options * number of questions This is essentially the same "password reset questions" loophole that allowed the apple cloud storage hack on a bunch of celebrities.
- DannoHung 11y agoI didn't say to use it by itself. I said that your OTP would be required first to even access it. And of course you could provide backoff. And then you'd also have to be answering a series of multiple choice questions all correctly. I dunno, just a thought, but do you get what I'm saying about recognition vs recall? Why don't we have the computer test us about things we're good at if part of the test has to be something only our individual brain is capable of?
- 100k 11y ago"Most people use passwords. Some people use passphrases. Bruce Schneier uses an epic passpoem, detailing the life and works of seven mythical Norse heroes." http://www.schneierfacts.com/fact/27 http://www.schneierfacts.com/fact/27
- 0x0539 11y agoI know you're making a joke but a passpoem or a passstory for lack of a better word is usable and something I do. I take a passage of reasonable length from a book that I've memorized, could be song lyrics or anything though. Then to create a password I take the first several words to make a password roughly the length I want, do a standard transformation on it that results in a string with numbers and special characters and use that as a password. When I need to change my password, I just take the next phrase from the passage and apply the same transformation. This has the distinct ability of letting me go back in time and remember what password I would have used at a certain time which has come in handy for remembering the root password on an old server.
- LoSboccacc 11y agoLoL at 'discover' http://security.stackexchange.com/questions/22717/how-secure-are-passwords-made-of-whole-english-sentences http://security.stackexchange.com/questions/22717/how-secure... I think we should held a competition to find out how old this tibit of knowledge really is and also the oldest article about security experts demonstrating passphrases are wide open to dictionary attacks. 1982 reference on passphrases http://www.sciencedirect.com/science/article/pii/0167404882900256 http://www.sciencedirect.com/science/article/pii/01674048829...
- DanBC 11y agoPassphrases are not wide open to dictionary attacks.
- pdabbadabba 11y agoThis isn't just about pass phrases, or using a whole sentence as a password. The new part (to me, at least) was using short nonsense poems complete with rhyming and meter. This makes it easier to remember longer phrases/sentences. Not that the idea is hugely innovative, but it strikes me as helpful, and not already well worn.
- thinkmoore 11y ago"If you want your own little poem password, you can enter your e-mail here, and their program will send you a secure one, which will then be deleted from their server." Uh... They went through all the trouble of making a website. Maybe use https and just show me the password on the website?
- A010 11y agoI assume this part is just a joke.
- untothebreach 11y agoNo https, but there is this: http://www.isi.edu/natural-language/people/poem/poem.php http://www.isi.edu/natural-language/people/poem/poem.php The "email me a password" service also currently has a note on it that says "Note: Site is super busy! Approximate waiting time: 269 hours."
- DennisP 11y agoProviding open source code would be a lot more helpful. Maybe they want to make a commercial product out of it.
- jobu 11y agoEdward Snowden mentioned using a pseudo-random phrase like MargaretThatcherIs110%SEXY in his interview with John Oliver: https://www.youtube.com/watch?v=yzGzB-yYKcc https://www.youtube.com/watch?v=yzGzB-yYKcc
- aclissold 11y agoBut surely you can't remember a different poem for every service that requires a password? Relegating you to use a password manager anyway, at which point you might as well just generate random passwords that don't rely on dictionaries?
- rnovak 11y agoWhy not? we can remember the lyrics to every single song we like, or the dialog from some stupid show from 20 years ago, but pass-phrases are out of reach?
- foz 11y agoWe remember the songs and TV shows because we listen and watch them, repeat them in our heads, talk about them with friends. We dont do that with passphrases. Just continue to use a password manager, and save the poems for your master password, your ssh key, your unix account, etc. Only then do you need to recall on demand.
- rnovak 11y agoCreate a single-point-of-failure for my entire digital-life? Thanks, I'll pass. People are completely free to use password managers, but that's their individual choice. Additionally: There are how many songs in existence today? Apparently some tech dude said there are >97 million. [1] How many of those are lyrical? How many unique excerpts are possible of those lyrics? You can chose an excerpt of your favorite song as a pass-phrase, and the chance of a computer guessing that is infinitesimal (though this statement is very hand-wavey without any maths to back it up), and it is supremely easy to remember. It's also highly unlikely that you'll ever share it with anyone on the planet, let alone the same site (also hand-wavey). If you're smart enough to remember more than one song, you can probably build up several pass-phrases that are supremely easy to remember, nearly impossible to guess, and easier to type than some rando-group of characters. Like I said, you/anyone is free to use a password manager, but I'll continue to prefer other means. [1]http://www.marsbands.com/2011/10/97-million-and-counting/ http://www.marsbands.com/2011/10/97-million-and-counting/
- kristopolous 11y agoEveryone who is serious about passwords should run a cracker for a week or so on some large set of passwords. You end up getting a pretty good sense on what falls quickly.
- kisstheblade 11y agoI was wondering what the real "entropy" (?) for these kinds of passwords is? If you take the vocabulary of common words (ie. not generated from a list of eg. 300k words like in the article), aren't the permutations rather small? If some person just makes these four words up from words they know (and probably use quite regularly) Eg 10000^4 or even 1000^4 (for those types who would use "password" otherwise)? Isn't that quite bad or am I understandig something incorrectly?
- DanBC 11y agoLook at something like Diceware. You have a list of 7776 words. You roll dice to select words. You're recommended to use 7 words or more. That's plenty secure for most passphrases, even if the attacker has the exact same wordlist as you do.
- deleted 11y ago[deleted]
- drabiega 11y agoIf you include names, the word list becomes pretty immense. Most of the words any one given person knows are names. If you include at least one name, you're pass phrase is pretty secure.
- daleco 11y agoI was thinking about that... The average person is using 5000 words. We could assume that the poems do too. (5000^4/ (300,000,000,000))/(60*60) = 0.57 hour with 4 words at 350 billion guess per second (http://arstechnica.com/security/2012/12/25-gpu-cluster-cracks-every-standard-windows-password-in-6-hours/ http://arstechnica.com/security/2012/12/25-gpu-cluster-crack...). 1300 years with 6 words.
- samstave 11y agoIn 1997 I inherited a network which had a password I needed to recover... It was some Cisco Device -- I cant recall model number or how we recovered the password; but Ill never forget that password: FeetFourMonkey
- syoc 11y agoThe problem with passphrases are wordlists and combinator attacks. This is been known for a long time. This headline is very misleading and I hope no one use passphrase-based passwords for extremely sensitive data.
- DanBC 11y agoCan you describe how a wordlist and combinator attack is risky for something like eg diceware? Let's make it easier and assume the diceware list only includes the 26 lower case characters (nothing else), that all words are separated by a single space, that the passphrase contains 7 words. And we assume our attacker knows all of this, and has the same wordlist we used. Heck, we'll even give them our dice too. How at risk is our 7 word passphrase?
- ph0rque 11y agoThe biggest drawback is that many sites these days limit the number of characters that you can use in your passwords, so these poems are probably too long for many of your accounts. But perhaps that will change someday soon. More and more sites are considering dropping the character limit, since shorter passwords are a lot less secure. This is my biggest pet peeve. Actually, my second-biggest. My biggest is when registration silently fails because the password was too long.
- clentaminator 11y agoTop for me are sites that silently truncate part of the end of a new password without informing you, then leaving you logged in thinking that the registration process completed successfully.
- beeboop 11y agoWells Fargo's website did this to me. It's ridiculous how crappy their website is.
- steeef 11y agoThe same could be said for the majority of financial institution websites. It's ridiculous how insecure and behind the times they are. Behind password restrictions, I'd say the next biggest thing that angers me is that they claim to support two-factor when it's really just "Wish It Was Two-Factor" in the form of so-called "security questions": http://thedailywtf.com/articles/WishItWas-TwoFactor- http://thedailywtf.com/articles/WishItWas-TwoFactor-
- guelo 11y agoNot only that but many sites force you to add punctuations numbers and capital letters. Tr0ub4dor&3 is the only style of password allowed.
- redblacktree 11y agoParticularly since there is no reason to limit password length unless you're storing them in the clear. Hashes are all the same length.
- zeveb 11y agoIt's a bit disappointing that they're focusing on 60-bit passwords; a 128- or 256-bit security level is best for securing important data.
- DennisP 11y agoMemorize two poems.
- dogma1138 11y agoThat only works against basic bruteforce attacks, if you are using hybrid attacks those passwords become easier to crack. What people don't realize that professionals who crack passwords for a living use quite sophisticated techniques using known information about the target, common masks, and patterns makes cracking specific passwords easier than just bruteforcing them. If you use a 300K words dictionary and know or can assume that the paraphrase will be constructed out of 3-5 words the password entropy isn't as large as just thinking this is a single case or mixed case alpha with say 12-16 characters. When dealing with generic password your basic unit is a character so a 16 char password is made out of 16 units each of those has a specific search space single case alpha it's 26, mixed alpha it's 52, single alpha numeric it's 36 and so on. Here you have 3-4 units each has a fixed search space and that's the dictionary you use, the search space can be even more restricted if we can assume certain things about the algorithm that generated the passphrase. If we take the poem example we can assume that words will not appear more than once in the passphrase and that they might need to rhyme this alone can reduce the password entropy considerably. If we take other examples like story based passphrases e.g. "the quick brown fox jumps over the lazy dog" then we can base our assumptions based on what we know of the English language for example that words like "the" will appear at least once in such sentences as well as take some estimates about how many verbs, nouns, and pronouns will appear on average in each sentence based on their common distribution which allows you again to reduce the search space considerably. Passphreases are still great when you need to ensure that your passwords won't be broken in bulk when a breach happens because unless your account is admin@ijustgothacked.com you most likely won't be a target and those types of datadumps are still usually broken through basic dictionary, masked and cheap bruteforce attacks. If you might be targeted directly or phished than passphrases might not offer any sufficient level of protection and could actually be weaker than an annoying mixed-alpha-num-special password. That of-course will change if everyone will start using passphrases if you expect that 50% of your hashed passwords dump is passphrases you will adapt your password cracking techniques accordingly.
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]