4 ms·
I don't really understand why this is even theoretically supposed to be a good method of making a password. I wish the article tried to explain that. Here are
by methehack 11y ago
I don't really understand why this is even theoretically supposed to be a good method of making a password. I wish the article tried to explain that.
Here are a few questions I have:
+ I understand that the pseudo-randomness of a computer is often accidentally way less random than the programmer thinks. So, the by-hand nature of these passwords seems like an
advantage, all else being equal. Right?
+ I thought real words were really bad in a password. Is the idea here that, with six words from these lists, the possible combinations are so great that the trade off is worth it because the password is memorable? That seems suspicious to me because you're essentially giving the cracker the list of possible passwords. Though that list may be quite long, it's still a list. Right?
+ These can't be better than the 30 character passwords I generate with 1Password, right? Unless there's a bug in 1Password... Maybe that's part of the point.
EDIT: list formatting (I hope).
- Tomte 11y agoDiceware gives you 12.9 bits of entropy per word. Do the math. Yes, your 1password password is stronger. But does it really matter? See http://world.std.com/%7Ereinhold/dicewarefaq.html#howlong http://world.std.com/%7Ereinhold/dicewarefaq.html#howlong
- Natanael_L 11y agoWords are not bad because they're words. They're bad because humans select them predictably. Entropy is what matters in the end. 30 random characters will have approximately 185.7 bits of entropy. With Diceware and the 7776 entry wordlist, that's 14 words to match it. Although 8-9 words is sufficient for most uses.
- dllthomas 11y agoEven properly selected, words are bad at "entropy per character". However, in most cases what matters is memorability rather than length. Words are pretty good for that, provided (as you note) you select the words well.
- theoduino 11y ago> + I understand that the pseudo-randomness of a computer is often accidentally way less random than the programmer thinks. So, the by-hand nature of these passwords seems like an advantage, all else being equal. Right? If /dev/urandom is seededed/used properly, then it will be good enough for passwords. The by-hand method is also good if your dice are fair. > + I thought real words were really bad in a password. Is the idea here that, with six words from these lists, the possible combinations are so great that the trade off is worth it because the password is memorable? That seems suspicious to me because you're essentially giving the cracker the list of possible passwords. Though that list may be quite long, it's still a list. Right? Well, by using only characters (and under a certain length, say 100 chars), you already have a list, so whatever you do, there is a finite number of valid passwords. The 6-word strategy is actually quite good. (I use this method for some passwords). The Arch Linux /usr/share/dict/british has 123398 words. 123398 ^ 6 = 3530601691883345409045950707264 possible passwords log(3530601691883345409045950707264) / log(2) is about 101.5 bits of randomness. Given 86 possible characters and a 14 character password (which you may not be able to remember), there are 1210537694726365245693116416 possibilities, which gives about 90 bits of randomness. > + These can't be better than the 30 character passwords I generate with 1Password, right? Unless there's a bug in 1Password... Maybe that's part of the point. Randomly generated passwords using all characters have a fatal flaw: one cannot easily remember them. If they're just being saved in a password manager, they are good, but you probably want a master password that you can remember, which is a good use case for these.
- DanBC 11y agoDICEWARE is a list of 7776 words. Each word is indexed by a five digit number. The five digit numbers are obtained by rolling 5 six sided dice. (11111 through to 66666). When it started a 5 word list was recommended. Now a 7 word list is recommended. Imagine a word list where all the words are lower case, and don't use any special characters. And our passphrase has 7 words, each separated by a single space, with no extra special characters or numbers. And also our attacker knows our wordlist and our passphrase rules. We have a phrase that is one of 7776^7 different phrases. This list is too long for a dictionary attack. It's really weak if we have 4 words or less. Ideally you'd have a long strong passphrase to open a password safe. It'd be great if people could invent really good tokens instead of passwords.
- Natanael_L 11y ago> It'd be great if people could invent really good tokens instead of passwords. U2F which the new Yubikeys supports?
- raevilman 11y agoDiceware passwords - Get unlimited of them https://play.google.com/store/apps/details?id=com.raevilman.diceware https://play.google.com/store/apps/details?id=com.raevilman....
- miles 11y ago> I don't really understand why this is even theoretically supposed to be a good method of making a password. I wish the article tried to explain that ... I thought real words were really bad in a password. A comment by "Hat Monster" on Ars explains why passwords generated using Diceware are secure: If you know your target is using a Diceware password, that is, you know the format is "english word, english word, english word, english word" you'd think it could have little entropy. Assuming that all entropy is only in the password, and the attacker knows exactly how you generated it, using which word list, and how many words long it is, this means each word, generated by 6^5 combinations, has 12.9 bits of entropy. Six words is 77 bits. 2^77 is large enough that a brute force attack on it at 1 trillion guesses per second (Snowden) would still take 151 trillion seconds, or 2.7 million years.
- lini 11y agoObligatory XKCD answer: https://xkcd.com/936/ https://xkcd.com/936/