4 ms·
This threat only holds for dedicated attackers. 1. They have to have multiple passwords to have a chance to derive the algorithm. 2. They also need to somehow
by jpfed 9y ago
This threat only holds for dedicated attackers.
1. They have to have multiple passwords to have a chance to derive the algorithm.
2. They also need to somehow think it's worth their time to reverse the algorithm instead of just going with lower-hanging fruit.
- donald123 9y agoThis is not necessarily true. Attackers with multiple sites' passwords can link users and look at their passwords. When they see some similarity of the passwords for the same user, it would take least effort for them to crack the password. Even if it only applies to dedicated attackers, think about the consequence, once the attacker cracks your password, he knows your algorithm, all your passwords will be exposed. And the point is the method is not more secure than using the same password for multiple sites.
- jpfed 9y agoYes, it really is more secure than exact re-use. Attackers that just try the exact same password on multiple sites on first discovery will be thwarted by algorithmically derived passwords. I'm not ruling out that there will be attackers that try to harvest passwords from multiple sites, join those sites by username or email, then try some ML to derive people's password algorithms. But there is a whole class of attackers that just won't bother with that level of sophistication. If your algorithm is any good, you're already not the slowest person running from the bear (cf. easy passwords or exact-password-reuse).
- donald123 9y agoHaving less hackers or taking hackers a little more effort to crack the password do not make it more secure in any ways. This is security through obscurity. Do you think the hackers will stop like a bear when they crack the first password? If password can be cracked, they are insecure, no matter it takes the hacker 10 minutes or 10 hours. And it does not take ML to derive these simple algorithms at all. People may think their password algorithm is good, but it lacks the fundamentals of cryptography. It's really just a puzzle you play with the attacker.
- pixl97 9y ago3. With Yahoo leaking billions of accounts, and hundreds of other services leaking 10's of millions of accounts, your passwords are already out there. 4. Someone makes a John the Ripper/Hashcat plugin that searches password dumps for common usernames/email addresses and attempts to determine if the password is based on an algorithm. 5. With advances in NLP AI, this will just get easier in the future.
- ythn 9y ago> and attempts to determine if the password is based on an algorithm. How is it going to do that? Especially since every website has different length and character requirements?