5 ms·
It is indeed no longer good advice, but not because of longer passwords not being better: https://www.schneier.com/blog/archives/2014/03/choosing_secure_1.html
by bwindels 10y ago
It is indeed no longer good advice, but not because of longer passwords not being better:
https://www.schneier.com/blog/archives/2014/03/choosing_secure_1.html https://www.schneier.com/blog/archives/2014/03/choosing_secu...
> This is why the oft-cited XKCD scheme for generating passwords -- string together individual words like "correcthorsebatterystaple" -- is no longer good advice. The password crackers are on to this trick.
- creshal 10y agoSchneier completely misses the point. The entropy estimates quoted by XKCD (and indeed, used by implementations) assume that the crackers are "on to this trick". For any given entropy you use to generate your password, xkcd-style passwords will be easier to memorize and type out.
- germanier 10y agoThis article is posted every time the comic is mentioned but I can't understand the argument. The calculation of password complexity in the comic is made with that in mind. It's assumed that the cracker knows the method used to generate the password, including the dictionary. The strength of this method does not rely on the fact that the password has many characters but that words are randomly chosen from a large dictionary. The attacker would need to do the same at minimum.
- thatdude 10y agoBut the words themselves follow an identifiable pattern (their spelling). As such, a 4 letter word in your password is cracked much quicker than a portion of your password being 4 characters of random info.
- creshal 10y agoThat only matters if, for some reason, your password is length limited. If your password must not be more than four letters long, then yes, choosing your tokens from an ascii table has the highest possible entropy. (Example: WPA2 PSKs, shitty websites.) If your password can have arbitrary length (or arbitrary enough, about ~120 letters), you can generate a 128 bit password with dictionary words as tokens. Sure, the password will be much longer (factor ~6), but also much easier to memorize.
- bwindels 10y agoThis is my understanding, could be missing something though: The comic proposes that correcthorsebatterystaple would be a secure password. It is 26 characters long and contains 4 basic english words that would be in even the smallest of dictionaries. Let's say a dictionary with 100.000 entries contains these words. Combining 4 words in the dictionary gives you 100,000^4 = 1.e+20 possibilities. Not bad, but let's say 15 random uppercase and lowercase (like the first letters of every word in a phrase like Schneier proposes) letters give you (26+26)^15 = 5.49e+25, still 5 orders of magnitude better. Edit: a phrase with 26 words in to take each letter from indeed isn't doable to remember, changed it to 15.
- germanier 10y ago100k words might be a bit to many for a dictionary of words that are easy to remember. The comic proposes using not enough entropy (i.e. you should use more than four random words). The Schneier method is basically equivalent but with important caveats: 1) Such a phrase is not randomly chosen but follows at minimum basic English grammar and at worst is well-known and thus part of the attacker's dictionary and 2) even if that is taken account for the first letters are not distributed uniformly across the alphabet, you just need to take a look at any (printed) dictionary. That greatly reduces entropy and makes it hard to reliably estimate entropy.
- creshal 10y ago> 100k words might be a bit to many for a dictionary of words that are good to remember. I've been generating all my (memorized) passwords from a 120k word dictionary for years now, can't complain. And estimating the entropy is easy.
- germanier 10y agoEasy entropy calculation is the beauty of that method. But for "take the first letters in an English phrase" you can't just do (2*26)^{length} or you are way overestimating.
- hollander 10y ago
- Robin_Message 10y agoArgh, no! Entropy. It's all about entropy calculation. There is no trick. Look at it this way: - choose 68 bits at random. This is findable by a nation state; if they are your adversary, add a couple more words. - split those bits into 4 17-bit numbers (17 bits has a maximum of about a hundred thousand) - your password is 4 words from a hundred thousand word dictionary - there is no trick: you've encoded 68 random bits securely, and guessing just those bits is pretty impossible. Schneier is normally sensible but calling entropy a "trick" is idiocy.
- creshal 10y agoOr with actual code: https://github.com/creshal/yspave/blob/master/yspave/pwgen.py https://github.com/creshal/yspave/blob/master/yspave/pwgen.p... A password generator does not care whether its input alphabet is \d, \w, all emoji codepoints, or `cat /usr/share/dict/words`. You determine the entropy of it, and then output as many tokens as needed. It doesn't matter whether an attacker has a copy of your input alphabet, or knows your algorithm. You defeat him by setting the entropy bar high enough (and using a cryptographically secure RNG to generate it). But a random selection of /usr/share/dict/words (~120,000 entries on Arch Linux) will be easier to memorize than a random selection of the ascii printable range.
- michaelt 10y agoHasn't it always been the assumption that password crackers know about the trick? If I choose 4 words from a dictionary of 50,000 words [1] that produces 50000^4 possible passphrases. That's equivalent to 62 bits of entropy, or a 10-character [a-zA-Z0-9] password. About 8 years to brute force on MD5 with 2x AMD HD 6990. And obviously an extra word makes it take thousands of years. It's not ideal, but it's better than a lot of password advice. [1] cat /etc/dictionaries-common/words | grep -v "'s" | egrep -v 's$' | wc -l gives me 51726
- creshal 10y ago> | grep -v "'s" | egrep -v 's$' Why filter those out?
- reacweb 10y agoall the 50,000 words will not be chosen with the same probability. I think we are more like a random 8 characters [a-zA-Z0-9] password.
- creshal 10y ago> all the 50,000 words will not be chosen with the same probability. Why?
- reacweb 10y agored hammer effect.
- creshal 10y agoHow does that affect /dev/random?
- snowwrestler 10y agoThe XKCD comic skips lightly over this by simply stating that the words were randomly chosen. But being truly random is actually hard for most people to do off the tops of their heads. I doubt many people are taking away from that comic that they should use software to reliably randomly choose the words they memorize. Instead the advice seems to usually get shrunk down to "choose 4 random words," i.e. out of your own head. Most people don't carry 50,000 word dictionaries around in their heads. More like a few thousand. That changes the math considerably.