6 ms·
This is not a good suggestion on their part, and has long been proven ineffective: Substitute numbers for letters that look similar (for example, substi
by magoon 10y ago
This is not a good suggestion on their part, and has long been proven ineffective:
Substitute numbers for letters that
look similar (for example, substitute
“0” for “o” or “3” for “E”.
- SNvD7vEJ 10y agoNoticed that too. If this is what their "security team" recommends, they might need to upgrade the team.
- matt_morgan 10y agoYeah, really. They also don't say another important thing, which is never use the same password in two different places. Maybe they think nobody will listen, but after seeing that other dumb advice, I don't have much faith.
- ethbro 10y agoI've never used it, but assume it's TeamViewer-esque? From the quote on their front page, assuming their target audience is of the "mycat00" at the best variety.
- hackuser 10y ago> This is not a good suggestion on their part, and has long been proven ineffective: Agreed; that is bad advice. I tell people: If you think of a trick then the attackers, who have expertise and think about these issues all the time, have thought of it long ago and have written it into their password-cracking software. That applies to visual substitutions (such as GoToMyPC recommended), phonetic substitutions (e.g., AmeriKa), patterns on your keyboard, etc. In a more technical sense, that applies to tricks that can be defeated with an algorithm and affordable computing resources.
- shabble 10y agoAre there any good sources on what sort of generative trickery a good cracking tool will use? I've noticed that the OSX Keychain 'memorable' password suggestions are almost always /(\w+\d+[[::punc::]]+\w+)/, which is enough of a pattern to probably make an explicit generator for which will match much faster than a naive brute-force.
- hackuser 10y ago> Are there any good sources on what sort of generative trickery a good cracking tool will use? Two answers: 1) It's not worth trying to keep up with, unless that's your specialty. There are people who spend days thinking up attacks; how much time will you need to spend to keep up with them? Far more time-effective than trying to anticipate all the specific attacks is to use provably secure defenses: Passwords that are mathematically too expensive to brute force, and which cannot be guessed by other means (e.g., by knowing personal information about you). That shifts the weak link from your password to the security of your OS, network, and applications, which probably have a couple of holes in them. 2) This will give you an idea of the scope of possible attacks. Note that it's 9 years old: https://www.schneier.com/blog/archives/2007/01/choosing_secure.html https://www.schneier.com/blog/archives/2007/01/choosing_secu...
- saidajigumi 10y agoNote that what you're really looking for is the amount of entropy in the encoding. So for many 'memorable' encodings, the password does need to be longer vs. an alphanumeric+symbols password, but still encodes the same number of bits of entropy. Diceware[1] is a nice example of how such a system works, and how you can generate a strong 'memorable' password by hand (and dice ;-). In short, there's a dictionary of short words, letter combinations, and numbers that form the "symbols" of the generated password. A random input (here, rolls of dice) are used to select a series of symbols. You could just as well create your own table and generate the password from that, but if you've got enough randomness as input then it doesn't so much matter what encoding you use. In fact, the general assumption is that you should assume your attacker knows your encoding. [1] http://world.std.com/~reinhold/diceware.html http://world.std.com/~reinhold/diceware.html
- sandworm101 10y agoBut if the trick you are using results in sufficient entropy, it shouldn't matter that the enemy has thought of it too. I'm still a fan of linking common words together as this results in easily-memorized passwords with very high entropy. "Catrunningfishhostagelaptop" is a good password these days. it is easily remember but also difficult to brute force even if you know the trick by which it was constructed. (And yes, by putting it out there I realize it is now a bad password.)
- voltagex_ 10y agoCouldn't I write a bruteforcer that instead of 5 * letters, tried 5 * dictionary words and get your password easily?
- vitno 10y agoThere are a lot more words in the dictionary than letters.
- DerfK 10y agoThe question is whether people are all going to pull words from a very small pool or form sentences to cut the search space (adjective noun adverb verb noun). A search space of 2000^5 (2000 most common words without punctuation) is still about 20 times larger than 80^8 (upper/lower/number/symbols)
- sandworm101 10y agoFive or six words is a huge amount of entropy. In reality there are other rules in my example than just using words. It starts with a capital letter and includes a conjugated verb (running) both of which increase complexity considerably. And it of a random length, having taken its length from my selection of words rather than from any fixed policy. Few services accept random lengths but imho all should. There is a great scene in DoctorWho where a door password is a series of concepts (spoken mentally) that one thinks about in a particular order. Fiction, but the person writing that scene knew a thing or two about password complexity.
- btgeekboy 10y agoThis is what I tell people about the + notation in their email addresses. Spammers know what it's for, and can easily strip it out if they wish to conceal their address source.
- steveeq1 10y agohttps://xkcd.com/936/ https://xkcd.com/936/