4 ms·
Far be it from me to contradict Bruce Schneier, but he doesn't actually give a good reason why the XKCD or diceware scheme is bad. He seems to be saying that it
by ascorbic 11y ago
Far be it from me to contradict Bruce Schneier, but he doesn't actually give a good reason why the XKCD or diceware scheme is bad. He seems to be saying that it's not as good as a 25 character random string, which is true, but that's not what is claimed. Even if the attacker knows your word list, and knows that you've chosen four of them, if you've chosen them randomly then there's still easily enough entropy to make it unrealistic for them to crack it.
- digi_owl 11y agoAnd that seems to be an ongoing issue with -sec debates. That the people "inside" are so focused on "perfect" protection, that they see anything else as worthless. There was someone here on HN just the other day that basically decried a scheme for using multiple user accounts to "sandbox" programs as useless because it would be ineffective against "state actors" (aka NSA and their equivalent). This even though it would likely foil, or at least reduce the impact of "drive by" attacks aimed at accessing personal information for identity theft etc.
- danesparza 11y agoWell, he does explain it: "Modern password crackers combine different words from their dictionaries" And then he goes on to give his advice (of using a password manager or a piece of paper, etc). Is it that advice that you're contradicting? You also said "..but that's not what is claimed". Are you referring to the implied claim in the original XKCD cartoon (https://xkcd.com/936 https://xkcd.com/936) or something else? I'm just trying to understand.
- ascorbic 11y agoThe whole point of this scheme is that it doesn't matter that password crackers know about it. It would matter if we were comparing them purely on the number of characters, but that's not the basis that either XKCD or this site calculates the entropy. Four words from a list of 5000 gives 49 bits of entropy. That means there are 2^49 possible passwords (~500 trillion) even if you know the wordlist.
- omh 11y agoModern password crackers combine different words from their dictionaries But the XKCD cartoon is working on the assumption that this is exactly what the attacker is doing. Despite that, they would have to do more work than to crack the "Tr0ub4dor&3" type password. I think Schneier just got the wrong end of the stick here. The XKCD reasoning seems valid to me.
- falsehorsebatte 11y agoI don't necessarily want insolence being trivially linked to my real life account, hence the throwaway. There are some issues: First, what he says is that "password crackers are on to this trick". Knowing the trick doesn't automatically render a scheme ineffectual. If it did, public key crypto wouldn't work (and the proposed scheme for generating passwords wouldn't be any better, anyway). Second, the article he's citing is an Ars one about the state of the art in password cracking in 2013, which gave a flawed synthesis about the XKCD/diceware scheme based on a misunderstanding of it. Take a look at the list of cracked passwords given as examples, and see if you can find a single one that would have been generated using that scheme. One of the main takeaways of the Ars article was that the XKCD/diceware scheme is broken. A reference to the XKCD strip is featured prominently in the the main graphic, but the mention of it only shows up on page 3. Examining their methods shows the link from their methods to their conclusion to be a tenuous one. Calling it tenuous is actually being generous, because it's more like a false link. Here's where it gets called out: Early in the process, Steube couldn't help remarking when he noticed one of the plains he had recovered was "momof3g8kids." [...] Other times, they combine words from one big dictionary with words from a smaller one. Steube was able to crack "momof3g8kids" because he had "momof3g" in his 111 million dict and "8kids" in a smaller dict. "The combinator attack got it! It's cool," he said. Then referring to the oft-cited xkcd comic, he added: "This is an answer to the batteryhorsestaple thing." This suggests that the cracker doesn't understand what the comic strip is advising readers to do when generating passwords. Now some closing remarks about this research in general. When the Ars article was published I waited for someone to call it out, but didn't find anyone doing that. I waited some time to look again and turned up nothing. That is disappointing, but fine, I suppose. However, the particular way that the security community builds up reverence for individuals and discourages re-examining past results is troubling. When I see how big of an effect the conclusions of one guy and the journalist that wrote about him in a popsci news source have, and when I see that some people have an itch to challenge those conclusions but don't put them out there, I'm reminded respectively of Feynman's motivation to write about cargo cult science and to warn us against the kinds of things that happened with Millikan's results and the oil drop experiment. People shouldn't feel they need to turn away from an argument just because they see those on the other side citing Schneier, and the community needs to do better about not encouraging the growth of unassailable celebrity or creating sacred cows.