3 ms·
Honest question: does password strength actually matter that much in practice? Do people using "horse" get hacked more often than using "zjh5?&Dp"? Is there a
by bertr4nd 10y ago
Honest question: does password strength actually matter that much in practice? Do people using "horse" get hacked more often than using "zjh5?&Dp"? Is there a point of diminishing returns where "horse23" is basically good enough? Has anybody studied this in a systematic way?
- Cursuviam 10y agoYes, if an attacker gets a dump of hashed passwords, horse will be tried much sooner than the other example.
- Bartweiss 10y agoI believe the studied answers are yes, yes, and yes. Ars Technica has some good articles on this. Generally, individual accounts don't get compromised at all unless they're a high-profile target, at which point guessable passwords become an issue. If you're a diplomat, CEO, or celebrity, you might get hit if you use "Password" or "123456". Otherwise, lockout rules and a general lack of interest will probably save you. The real risk comes when hashed password sets get dumped. At that point, people start attacking the entire set to see how much they can crack (this is what the Ars articles were about), and this is where password security becomes a big deal. As I remember, the common attack workflow is something like: 1. Throw a top-200 password list at the dataset. (Lulzsec did this then named-and-shamed exclusively people with bad passwords.) 2. Dictionary attack on one-word passwords. 3. Dictionary attack on two-word passwords and one-word passwords with common tweaks (i.e. first-letter capital, trailing numbers). (I consider the XKCD somewhat misleading, since an alteration to bar pure-dictionary attacks remains a useful addition.) 4. Expansive dictionary work: common but nontrivial adjustments like o/0, l/1, or scattered capitals. 5. Brute force all short passwords. <6 character is easy to break outright, and "smart" force (e.g. all 2 character combinations after common words) will get you many longer passwords. For unpredictable passwords, 8-10 characters is the inflection point on attack length. All of this goes basically unchanged with salting, it's just harder (and often, gets easier as you compromise a few salted passwords). So yes, this stuff matters in predictable ways. Pretty much all of it is defense against password dumps, in which context it definitely matters. And in that context, password managers remain king - they'll block even dedicated attacks on a single user.