4 ms·
Your first link uses a few assumptions that are very good security practice but may confuse the unexperienced reader: It assumes that the attacker has complete
by tashbarg 8y ago
Your first link uses a few assumptions that are very good security practice but may confuse the unexperienced reader:
It assumes that the attacker has complete knowledge of the password generation method. This is good security practice and provides you with a worst case boundary. In reality, though, an attacker seldomly has that advantage. Before an attacker spends x hours/days/weeks to crack pure word-based passwords, they will spend time to crack "passw0rd". If you remove the advantage of password generation method knowledge, all numbers in this article are very different. The reader should know about that!
It assumes that whoever is storing the password may do so badly. It even states "assume the site stores our credentials in the weakest possible way". Which is a dangerous assumption since the weakest possible way would be plaintext and then the whole article would be moot. So, obviously we exclude plaintext. The article goes with simple, single md5 hashes instead. While some kind of worst case, it's pretty unrealistic nowadays that someone makes an effort not to store passwords in plaintext and then fails so miserably in googling how to do so. This worst case is probably chosen to have easier and more impressive cracking numbers. The reader should be aware of this.
It assumes that the attacker obtains the password database. Again, good security practice and a worst case scenario. But still not exactly 100% realistic. If you argue with this assumption, the reader should be aware of that.
In essence, this article proves that the "3 word method" is not secure enough when absolutely everyone uses this exact same method (with knowledge of the exact same words) with a service who incompetently stores passwords and got its password database stolen.
While that is true, the advice it gives "Don't use words in passwords. Ever." is just another example of great oversimplification that is harmful in the end.
Instead of bashing methods for being not secure enough (whatever that means), we should provide users with practical methods to come up with usable passwords that are reasonably secure for the service in question.