13 ms·
The longer passwords in the Last.fm database
- fotcorn 10y agoKind of counters the idea from this xkcd comic that longer passwords are better, even when they just contain dictionary words: https://xkcd.com/936/ https://xkcd.com/936/
- rguillebert 10y agohow so?
- ProfDreamer 10y agoI think the problem with the longer passwords in this list is that they're well known phrases like song titles or just repetitions of the username.
- creshal 10y agoAdditionally, last.fm used unsalted MD5 hashes, which are so trivial to break it's not funny any more. (john manages 24 million hashes/second on my five years old laptop for that, even crypt(3) with md5 is three orders of magnitude harder to brute force.)
- baldfat 10y agoIt I still don't understand how this gained traction. I memorize 3 passwords and they are extremely hard. The rest are not created by me and I don't have repeated passwords.
- creshal 10y ago> I memorize 3 passwords and they are extremely hard. Not everyone is a masochist. It doesn't matter whether you encode 128 bit entropy in a base95 string, or a list of ~8 random words, it's still 128 bit entropy… but the word list will be easier to memorize and to type out.
- baldfat 10y agoHow many websites? How many passwords are you going to memorize and how are you going to not repeat a password?
- creshal 10y ago> How many websites? Zero. Why would I bother memorizing them? > How many passwords are you going to memorize The LUKS password for my home laptop, the LUKS password for my work laptop, logon passwords words for each, and password manager master passwords for each. I guess I could move some of these to hardware keys, but I'm too lazy. > how are you going to not repeat a password? The same anyone is not repeating passwords: Strong password generators.
- germanier 10y agoHow? The passwords on the list might be long but that's the only thing they share with the method from the comic. Usually they are just the same short phrase (often well-known) repeated a few times. This is not what that comic suggests.
- DanBC 10y agoNot a single one of those phrases are a random mix of dictionary words.
- bwindels 10y agoIt is indeed no longer good advice, but not because of longer passwords not being better: https://www.schneier.com/blog/archives/2014/03/choosing_secure_1.html https://www.schneier.com/blog/archives/2014/03/choosing_secu... > This is why the oft-cited XKCD scheme for generating passwords -- string together individual words like "correcthorsebatterystaple" -- is no longer good advice. The password crackers are on to this trick.
- creshal 10y agoSchneier completely misses the point. The entropy estimates quoted by XKCD (and indeed, used by implementations) assume that the crackers are "on to this trick". For any given entropy you use to generate your password, xkcd-style passwords will be easier to memorize and type out.
- germanier 10y agoThis article is posted every time the comic is mentioned but I can't understand the argument. The calculation of password complexity in the comic is made with that in mind. It's assumed that the cracker knows the method used to generate the password, including the dictionary. The strength of this method does not rely on the fact that the password has many characters but that words are randomly chosen from a large dictionary. The attacker would need to do the same at minimum.
- thatdude 10y agoBut the words themselves follow an identifiable pattern (their spelling). As such, a 4 letter word in your password is cracked much quicker than a portion of your password being 4 characters of random info.
- creshal 10y agoThat only matters if, for some reason, your password is length limited. If your password must not be more than four letters long, then yes, choosing your tokens from an ascii table has the highest possible entropy. (Example: WPA2 PSKs, shitty websites.) If your password can have arbitrary length (or arbitrary enough, about ~120 letters), you can generate a 128 bit password with dictionary words as tokens. Sure, the password will be much longer (factor ~6), but also much easier to memorize.
- DCKing 10y agoThe XKCD comic is showing its age. The comic mentions 1000 hashes per second. Assuming the entropy estimation is accurate (is it?), and it would take 550 years with 1000 guesses per second, that's still not very impressive. A single AMD Radeon Pro Duo graphics card can perform an estimated 8 billion guesses per second on the password hashes (unsalted SHA-1). A sub $10000 cracking rig with four of them can do 32 billion per second. That would mean the 550 year guessing time of XKCD's example password has been reduced to 9 minutes due to sheer computation power alone [1]. This is why it's important for everyone to use a slow and salted password hashing function (Argon2, scrypt, bcrypt, PBKDF2) to make sure that GPUs cannot guess hashes so terribly efficiently. Note that this even ignores any benefits attackers have had cracking a large amount of unsalted passwords, which will have been substantial. [1]: Edit: Looking up the current status quo, a single Nvidia GTX Titan XP can do almost 12 billion hashes per second in oclHashcat, that's 48 billion hashes per second for your cracking rig. Down to 6 minutes it is.
- Macha 10y agoThe comic itself mentions that it's intended threat model is someone trying to remotely login to your web server/ssh whatever, not trying to decrypt stolen hashes. I doubt any web service lets you try 32 billion logins/sec.
- creshal 10y agoIdeally you generate the password for your password manager XKCD-style, and let the password generator spit out 128 bit ASCII passwords for everything else. Then an attacker needs to get a sufficiently recent copy of your password database first, and password managers can afford using much higher work factors for their master password than websites for every single user.
- snowwrestler 10y agoThe gulf is so vast between how humans use a web service and how an automated brute force attempt uses a web service, that it should be trivial to block remote brute forces. Limit attempts to 1 per second per user ID, and block IPs with 50 consecutive failed attempts per user ID. These should be invisible to a human, but totally stop the brute force of any but the most obvious passwords. These don't seem like they would be difficult to do, but I am shocked at how few web apps do this. Last I checked, Wordpress ships with no limits at all on login attempts, for example.
- atoponce 10y agoIt doesn't actually. It shows how badly flawed the XKCD comic is. The problem with the XKCD comic is that he advocates creating a passphrase without a random function. Turns out, with no surprise, the resulting passphrases are easy to guess, because they are predictable word sequences, phrases, or sentences. To illustrate, suppose you have a word list of 8,192 entries, and a cryptographically secure random function. Shannon entropy says that each word in that list then contains exactly 13-bits of entropy (2^13=8,192). According to https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a270c40 https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a27..., 8 Nvidia GTX 1080 GPUs with Hashcat 3.0 can process 200 billion MD5 hashes per second, which means 5 of those password cracking rigs, working in concert, can do 1 trillion MD5 hashes per second. So, if you have a cryptographically secure random function choosing your words from that list of 8,192 words, what are we looking at? - 1 word (13-bits): 1 in 8,192 possibilities - 2 words (26-bits): 1 in 67,108,864 - 3 words (39-bits): 1 in 549,755,813,888 - 4 words (52-bits): 1 in 45,03,599,627,370,496 - 5 words (65-bits): 1 in 36,893,488,147,419,103,232 - 6 words (78-bits): 1 in 302,231,454,903,657,293,676,544 There is no need to go any higher than that, as we'll see in a second. If the password cracker is only interested in searching 1/2 of the total combinations, then that means at each hash, after completion, there is a 50% probability that the password was found (on average). So, armed with this, it would take the password cracker: - 13-bits: < 1 second to search 1/2 the space - 26-bits: < 1 second - 39-bits: ~ .3 seconds - 52-bits: ~ 38 minutes - 65-bits: ~ 213 days - 78-bits: ~ 4,792 years It's reasonable to conclude that if your threat model is password cracking clusters working on leaked hashed password databases, and assuming the password is hashed with MD5, then at least 65-bits of entropy, or 5-6 words chosen from a list of 8,192 with a cryptographically secure random function, is a good target for a secure passphrase length. For what it's worth, Diceware has been promoting this approach for years now, where the word list is 7,776 entries (~12.93-bits of entropy per word), and the cryptographically secure random function is 5 fair 6-sided dice. The XKCD "correct horse battery staple" approach is just a simplified implementation, forgetting the random factor.
- germanier 10y agoIt does say "four random words". To be fair, that could be spelled out more clearly.
- jffry 10y agoSee previous discussion here: https://news.ycombinator.com/item?id=12409530 https://news.ycombinator.com/item?id=12409530 Notably, the passwords were stored as unsalted MD5 hashes, which even in 2012 was known to be a poor idea.
- thatdude 10y agoThanks for reminder. Likely couldn't crack these in SHA-1 (or without substantially more effort), let alone some of the more new age hashing algorithms. Still, it's impressive.
- mrb 10y agoUnsalted SHA1 is just as easy to brute force as unsalted MD5. There is maybe a ~30% speed difference. Now adding a salt would have made it ~2 millions time harder for these ~2 million unique passwords.
- creshal 10y agoOn a 2012 laptop with john 1.8: • 24 million tries/second for unsalted MD5 • 18 million tries/second for unsalted SHA1 • 80,000 tries/second for crypt-md5 (state of the art… in 1995) • 2400 tries/second for bcrypt (already becoming obsolete in 2012) • And a tremendous 100 tries/second for scrypt (then state of the art) So yeah, the ~30% performance hit roughly fits. But even md5 can be used much more intelligently than just salting, and would have been available in major programming languages.
- Sami_Lehtinen 10y agoStill scanning the MD5 key space 2^128 would take a while to brute force passwords. Of course it only takes time. But a lot of time. SHA1 is better, because it's 2^168 options. Also there's a problem, what if the data isn't in single block. Then you might find collision, but that collision might include something which can't be put in the password field, and therefore doesn't solve the problem. MD5 for PQKDEj52vGQVKudQaBMSewJ5MMifgaVxNYK9zsRTxMzBkyvompLMtgYCYv6SNzDE is cd5480cf1ad1cf7fab3aedbc6495609d. I would love to see someone to reverse that. Even if you find the colliding hash with sorter set of input bits. It's highly likely, it won't be in the acceptable character set. Or am I getting something wrong?
- elaus 10y agoInterestingly, many of the longest passwords follow the same principle: A sentence repeated three times with two scrambled letters in one word each.
- germanier 10y agoThat might be an artefact of how they were found. Note that the page says "a few of the longer passwords". It's likely that they specifically searched for passwords using that principle.
- deleted 10y ago[deleted]
- INTPenis 10y agoSentences usually have whitespaces between words though, makes the passwords much easier to remember and handle. I'm assuming last.fm does not support blanks in their passwords since none of these passwords use that character. Or perhaps very few people realize you can use that character to help make passwords more manageable. My recommendation to people who ask the past few years has been full, grammatically correct sentences.
- foliveira 10y agoThey do support spaces. There's one password with 39chars down the list (about an "unveiling")
- Jugurtha 10y agoThe problem is that the vast majority of websites I've seen handle the whole process involving passwords horribly (registration, resetting, etc), which induces users to use bad passwords just to get it over with. Some let you fill out the form and then click on submit and tell you a problem with your password or something. You change it, then they tell you it has to be shorter than 15 or 10 characters, and impose such conditions you almost wait for them to tell you "use: 2Hx,!rJ" as your password. Some don't even support "special" characters, spaces, or hyphens. By the 4th or 5th attempt to register, you're basically trying to come up with the stupidest password you can to feed this monstrosity. Mind you, somme of these are big companies websites. I think password or registration management also affects things like talent acquisition. Companies using Taleo for instance are doing a great job of repulsing normal, mentally sane, people. The whole approach of registering one account for each company on a different company subdomain on the same domain (company1.taleo.net, company2.taleo.net) and for each one fill out the profile all over again is beyond the realm of my comprehension. The browser asks you to save the password/username for the website, but it does so for the domain, not the subdomains which all have different passwords. I give up on a company if it's using Taleo. I'm not talented or competent, but I'm sure really competent people wouldn't want to put up with this either and it hurts recruiting.
- Desustorm 10y agoWould be really interested to know how they cracked these passwords...
- creshal 10y agoBrute forced them?
- manmal 10y agoI really doubt that they brute-forced alapdanceissomuchbetterwhenthestripperiscrying. I have no exact idea, but I guess i would take 1000s or millions of years to bruteforce 1,22680068e65 combinations (taking only lowercase letters into account), if you don't have a working quantum computer available. UPDATE: I did some rudimentary math and think that top notch server farms would take something like 1e35 to 1e42 years to bruteforce 26^47 combinations.
- pilif 10y agoAt first I was really impressed by `1qaz2wsx3edc4rfv5tgb6yhn7ujm8ik,9ol.0p;/`, but then I watched my keyboard and all became clear. These brute force tools are getting better and better at trying useful combinations to the point where I think all "clever" are now known to the tools and the only thing that remains is completely random passwords as they are generated by password managers. Thank you for posting this list - this is very enlightening.
- venning 10y agoThis is known as a "keyboard walk" and its variations are one of the more common patterns tested for.
- curiouscats 10y agoI wonder if Dvorak keyboard walks are also targeted?
- venning 10y agoI'm guessing not. Your comment is my first result in Google search for "keyboard walk" dvorak. Edit: Ars Technica had a piece a while back on crackers and how they build their lists of probable passwords. I imagine if Dvorak-based passwords became common, they wouldn't last long as "secure" before appearing in those lists. Edit: The Ars link follows. You'll notice that the password in the story title is a keyboard walk, which the writer confuses as being complex, when it is not: http://arstechnica.com/security/2013/05/how-crackers-make-minced-meat-out-of-your-passwords/ http://arstechnica.com/security/2013/05/how-crackers-make-mi...
- stargazer-3 10y agoTo add to the ease of hacking around it, how the hell are you supposed to log in from a phone? Or a different keyboard layout?
- johnward 10y ago
- mickmock 10y agoI'd hate to be David Iceland right now....
- kalleboo 10y agoHad a good laugh at this one <script>alert(document.cookie);</script>
- facorreia 10y agoIt look like someone fishing for a vulnerability instead of a real password.
- chocolatebunny 10y agoWhy not both? I mean Robert');DROP TABLE students;--1 seems like a pretty good password.
- kazinator 10y agoI'm not laughing. This was probably an account created by a bot trying to detect the site's vulnerability to HTML injection. It makes sense for a password cracker to include some common such attack strings, so it can get any accounts that get created by such probing: very clever. A random, uncommon piece of programming language or markup language syntax would actually be a good password---you would think! I also wouldn't laugh if that were cracked.
- SamBam 10y agoIf it were a bot, why would they include the `alert`? That would freeze up the UI, and provide no more useful information than `console.log`. I'm guessing a human, who uses that password to see which websites are poorly coded.
- tempodox 10y agoThese passwords are just abysmal.
- andylang_ 10y agoLast.fm users are clearly big fans of Radiohead.
- ahmetkun 10y agono surprises there, Radiohead were always most scrobbled artist when i used the site actively. They probably still are.
- necessity 10y agoHow does leakedsource work? Basically they got password dumps and are selling this information to companies? Isn't this illegal somehow ?
- tom_v 10y agook, the first one is just priceless!
- DanielShir 10y agoLaughed at that one myself. It's an old Bloodhound Gang song - https://www.youtube.com/watch?v=YMGVMtnxXEw https://www.youtube.com/watch?v=YMGVMtnxXEw And there's the connection to last.fm :)
- tom_v 10y agoThat makes much more sense than this being just a random sentence!
- deleted 10y ago[deleted]
- circa 10y agoI had a good chuckle at the first one. alapdanceissomuchbetterwhenthestripperiscrying
- asciihacker 10y agoA password is just not enough. 2FA is almost a necessity I would guess.
- aleem 10y agoAny ideas on how they manage to crack these? I can't grok how they would achieve this via a dictionary attack, especially the likes of: MgihtyDutchmanMgihtyDutchmanMgihtyDutchman alapdanceissomuchbetterwhenthestripperiscrying <script>alert(document.cookie);</script>
- ryan-c 10y agoPassword cracking "dictionaries" can have phrases in them.
- aleem 10y agoI get that but permuting over typos, letter casing, lengths and combination of words would make the dataset huge. Is there a massively collaborated rainbow table database that is constantly growing? Are there other heuristics that come into play such as guessing the password length or some such thing?
- phpnode 10y agoRainbow tables aren't really a thing any more, you can calculate a hash much faster than you can download one
- mrb 10y agoBrute forcing tools (eg. Hashcat) can take lists of words, mangle them to simulate typos, concatenate them a few times. That's how the first password is constructed (mighty, dutchman). There is really not that many combinations to try: take the most common 2^13 English words, add 4 variations of each word to simulate 4 different typos (2^15 words), test all possible pairs of words (2^30 pairs), repeat each pair up to 4 times, and that's a total of only 2^32 candidate passwords, which takes 1-2 seconds to brute force with hashcat on a GPU rig. The 2nd password seems to come from a long dictionary: "a lap dance..." is the exact title of a song with no spaces and all in lowercase. It's good practice when brute forcing to take the titles of all known books, movies, songs... and put them in your dictionary. The 3rd password also seems to come from a dictionary, typically built by scraping a few million web pages and taking literally all strings separated by whitespace.
- jve 10y agoNot many special characters there. However still notes on what those tools try 1st: Some for keyboard walk, Some for xss thing, one dot at the end and parantheses or underscores seems not to help that much. Seems like today a password manager is a must.
- mnsc 10y agoI wonder how my password policy stands up? I have a memorized "satisfy stupid password rules"-string made up of lowercase, uppercase, digit, special character. Eg. pA5$word Then i take use "service name" [space] above string [space] "4-5 word sentence that first pops into my mind when i think about the service name" So for netflix I would get: netflix pA5$word the net is flickering Serves me well and I have never entered the secret string in any password manager, only the ending sentence. I can't autotype it though but since it's a sentence it's remarkably easy to type correctly. It also surprises me how often I remember the "first sentence that pops into my mind". The only problem I have with this scheme right now is services that don't allow something in this pattern (mostly no spaces) and forces me to deviate which makes my blood boil.
- anotheryou 10y agoDepends on what the threat is. For a brute-force dictionary attack: the "netflix" part is worth as much as a single random character, the length by the sentence will do you much good. The special chars are good. When a hack like this becomes public happens and someone tries to attack you in specific: the "netflix pA5$word" becomes worthless, but the sentence saves you. You forgetting stuff: the sentence will break your neck I guess a good master-password and a password save with random passwords is better, but you are doing pretty good! Also you can use a single password on a untrusted computer without fearing to compromise all other passwords too (again, thanks to that sentence).
- hollander 10y ago> His password: netflix pA5$word the net is flickering I don't get it that you say that "netflix" in this password has no more worth than a single character. How can the cracker know that this is "netflix" and not "netfli " or "neTflix"? Furthermore, it's not like the password reveals itself during the process. Untill all characters are found, there should be no logic in the result, or am I wrong?
- anotheryou 10y agoI thought he uses the unchanged service name as a prefix. If I had the chance bruteforce netflix accounts with a dictionary I'd definitely have "netflix" as one of my dictionary words to it (and Netflix and netflix.com and Netflix.com etc).
- venning 10y agoIf I know that I'm going to try to compromise a system and access its username/password lists, is there an advantage to creating a number of accounts to which I know the password prior to the break-in? Does this make it easier to break the other accounts once I have access to them encrypted? As in, I know that the account with username X has an unencrypted password Y, so now I have guideposts to tell if my cracking attempts are pointing in the right direction, trying to get back to password Y from the hashes. I imagine there would be something of an advantage to already knowing, say, 10,000 plaintext-encrypted pairs in a big list. If this is the case, should one be concerned in managing a system that sees a dramatic uptick in new user registrations as a precursor to an attack?
- snowwrestler 10y agoOnly if you are not able to characterize the hashing scheme, or if you think the app uses a static salt that you don't know. Then having a known plaintext would help figure it out. But I think you would only need one, not a ton of them. It seems like if someone hacks a system so badly that they get the whole DB, they can probably also figure out the hashing scheme while they are in there. I doubt that a dramatic uptick in new user registrations is a useful precursor signal.
- TheAceOfHearts 10y agoWell, this was a great promo for the people that built this site. I just paid $4 for a 24 hour pass to search view all the info of mine that's been leaked. Well worth the price in my mind. I'd love to scan my work's customer database for hits, in order to prompt those customers to reset their passwords. But I think $1k/month is too expensive for us. Does anyone know of any cheaper alternatives? In any case, it's a great service to provide. After one of the more recent leaks I ended up receiving emails from Pandora and Uber, prompting me to reset my password.