3 ms·
It doesn't actually. It shows how badly flawed the XKCD comic is. The problem with the XKCD comic is that he advocates creating a passphrase without a random fu
by atoponce 10y ago
It doesn't actually. It shows how badly flawed the XKCD comic is. The problem with the XKCD comic is that he advocates creating a passphrase without a random function. Turns out, with no surprise, the resulting passphrases are easy to guess, because they are predictable word sequences, phrases, or sentences.
To illustrate, suppose you have a word list of 8,192 entries, and a cryptographically secure random function. Shannon entropy says that each word in that list then contains exactly 13-bits of entropy (2^13=8,192). According to https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a270c40 https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a27..., 8 Nvidia GTX 1080 GPUs with Hashcat 3.0 can process 200 billion MD5 hashes per second, which means 5 of those password cracking rigs, working in concert, can do 1 trillion MD5 hashes per second.
So, if you have a cryptographically secure random function choosing your words from that list of 8,192 words, what are we looking at?
- 1 word (13-bits): 1 in 8,192 possibilities
- 2 words (26-bits): 1 in 67,108,864
- 3 words (39-bits): 1 in 549,755,813,888
- 4 words (52-bits): 1 in 45,03,599,627,370,496
- 5 words (65-bits): 1 in 36,893,488,147,419,103,232
- 6 words (78-bits): 1 in 302,231,454,903,657,293,676,544
There is no need to go any higher than that, as we'll see in a second. If the password cracker is only interested in searching 1/2 of the total combinations, then that means at each hash, after completion, there is a 50% probability that the password was found (on average). So, armed with this, it would take the password cracker:
- 13-bits: < 1 second to search 1/2 the space
- 26-bits: < 1 second
- 39-bits: ~ .3 seconds
- 52-bits: ~ 38 minutes
- 65-bits: ~ 213 days
- 78-bits: ~ 4,792 years
It's reasonable to conclude that if your threat model is password cracking clusters working on leaked hashed password databases, and assuming the password is hashed with MD5, then at least 65-bits of entropy, or 5-6 words chosen from a list of 8,192 with a cryptographically secure random function, is a good target for a secure passphrase length.
For what it's worth, Diceware has been promoting this approach for years now, where the word list is 7,776 entries (~12.93-bits of entropy per word), and the cryptographically secure random function is 5 fair 6-sided dice. The XKCD "correct horse battery staple" approach is just a simplified implementation, forgetting the random factor.
- germanier 10y agoIt does say "four random words". To be fair, that could be spelled out more clearly.
- atoponce 10y agoYeah, we need to be pedantic here. Humans picking words at "random" is far different from dice picking words at random. Turns out, human-randomness isn't very random at all.
- TheCoelacanth 10y agoAlso, "random" is often used colloquially to mean "arbitrary" which further muddies the waters for an uninformed reader.