2 ms·
Are there any good sources on what sort of generative trickery a good cracking tool will use? I've noticed that the OSX Keychain 'memorable' password suggestio
by shabble 10y ago
Are there any good sources on what sort of generative trickery a good cracking tool will use?
I've noticed that the OSX Keychain 'memorable' password suggestions are almost always /(\w+\d+[[::punc::]]+\w+)/, which is enough of a pattern to probably make an explicit generator for which will match much faster than a naive brute-force.
- hackuser 10y ago> Are there any good sources on what sort of generative trickery a good cracking tool will use? Two answers: 1) It's not worth trying to keep up with, unless that's your specialty. There are people who spend days thinking up attacks; how much time will you need to spend to keep up with them? Far more time-effective than trying to anticipate all the specific attacks is to use provably secure defenses: Passwords that are mathematically too expensive to brute force, and which cannot be guessed by other means (e.g., by knowing personal information about you). That shifts the weak link from your password to the security of your OS, network, and applications, which probably have a couple of holes in them. 2) This will give you an idea of the scope of possible attacks. Note that it's 9 years old: https://www.schneier.com/blog/archives/2007/01/choosing_secure.html https://www.schneier.com/blog/archives/2007/01/choosing_secu...
- saidajigumi 10y agoNote that what you're really looking for is the amount of entropy in the encoding. So for many 'memorable' encodings, the password does need to be longer vs. an alphanumeric+symbols password, but still encodes the same number of bits of entropy. Diceware[1] is a nice example of how such a system works, and how you can generate a strong 'memorable' password by hand (and dice ;-). In short, there's a dictionary of short words, letter combinations, and numbers that form the "symbols" of the generated password. A random input (here, rolls of dice) are used to select a series of symbols. You could just as well create your own table and generate the password from that, but if you've got enough randomness as input then it doesn't so much matter what encoding you use. In fact, the general assumption is that you should assume your attacker knows your encoding. [1] http://world.std.com/~reinhold/diceware.html http://world.std.com/~reinhold/diceware.html