7 ms·
Writing a Simple Password Generator in Racket
- MrLeap 8y agohere's my lazy PW script, written in node. :) require('uuid').v4().split('-').join('')
- minitech 8y agoWhy remove the hyphens? If that’s wanted, there’s the more direct: crypto.randomBytes(16).toString('hex')
- earenndil 8y agoThey don't _really_ affect your entropy that much (since the attacker doesn't know your character set in the first place), and some websites disallow certain characters.
- tomjakubowski 8y agoA funny little flaw in this is that 13th character of those passwords is always "4", right?
- deleted 8y ago[deleted]
- hoytech 8y agoAnd the character that was after the 3rd hyphen is always one of [89ab].
- giancarlostoro 8y agoIn Python for those who don't want to install node and run Debian / Ubuntu or any distro that includes Python out of the box: >>> import uuid >>> uuid.uuid4().hex Interesting someone else mentioned the 14th character is always a 4... I am creeped out just a little bit (cause I never noticed).
- Tostino 8y agoThat's because it indicates the version of uuid it is.
- deleted 8y ago[deleted]
- codetrotter 8y agoI wrote a passphrase generator once that I’ve been using ever since. It’s available on my GitHub page under a very permissive license. The README explains all there is to know about it but feel free to ask any questions anyone might have about it. https://github.com/ctsrc/Pgen https://github.com/ctsrc/Pgen
- firepoet 8y agoLovely! Here's a Clojure version of the same that I write: https://git.calmabiding.me/scstarkey/dicegen https://git.calmabiding.me/scstarkey/dicegen
- taeric 8y agoI was expecting something that would focus on the rules that so many sites impose. Length is easy, but many have silly rules where certain characters are not allowed. Then there is the side of making a password that is easy to type on a phone. Ideally, I want a hard password that doesn't require me to change input mode on my phone too many times. Well, ideally, I'd rather I could just use my security token everywhere... But that is a separate problem.
- bjoli 8y agoI have been thinking about that. How would one do that with a minimal impact on password security? Character sets are easy, but one could set some arbitrary limits on character frequency. I would probably generate a shitload of passwords and filter them based on the rules since that would mean not having to have complicated logic for password generation and thus not accidentally generating passwords that are less secure than the rule limitations.
- bjoli 8y agoI made this: https://pastebin.com/kQhKexEd https://pastebin.com/kQhKexEd in 5 minutes. It is however slightly off with the random distribution since I am only doing a simple remainder.
- andreareina 8y ago(let ((byte (remainder (get-u8 urandom) size))) is skewed if size isn't a power of 2. What you should do is mod by the next-largest power of 2 (e.g. if size is 82, mod by 128). Then if the result is in-range use it, otherwise discard and reroll.
- bjoli 8y agoI just edited the comment before I saw your answer. I realised my mistake and wanted to sink through the earth. Everyone has brain farts, I guess. What I ended up doing was limiting the charset size to 256 a maximum of characters, and then discarding any value that is larger than the current charset.
- VitoVan 8y agoI use a Bash Script copied from Stack Overflow: #!/bin/bash choose() { echo ${1:RANDOM%${#1}:1} $RANDOM; } { choose '!@#$%^\&' choose '0123456789' choose 'abcdefghijklmnopqrstuvwxyz' choose 'ABCDEFGHIJKLMNOPQRSTUVWXYZ' for i in $( seq 1 $(( 4 + RANDOM % 8 )) ) do choose '0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ' done } | sort -R | awk '{printf "%s",$1}' echo "" https://stackoverflow.com/questions/26665389/random-password-generator-bash/26665585#26665585 https://stackoverflow.com/questions/26665389/random-password...
- minitech 8y agoGenerating passwords with $RANDOM seems like an incredibly bad idea. In bash, it’s a Lehmer RNG seeded with the current microsecond and PID – and the seed is 32 bits. sort -R kind of saves it because it uses /dev/urandom + ISAAC, but it’s really not comfortable – 1/8 of passwords it generates are breakable in at most ~2^29 × 40320 attempts, for example (and the expected number could be much lower than that, I haven’t done the math).
- deleted 8y ago[deleted]
- easytiger 8y agoas opposed to a manually designed password?
- minitech 8y agoDepends on what your strategy for manually designing passwords is (yes, it’s that bad). But anyone who can figure out how to use this bash script can figure out how to use one of the `< /dev/urandom tr` scripts, pwgen, or a password manager.
- Pristina 8y agofor i in ["".join(random.choice(wordlist) for x in range(5)) for y in range(20)]: print (i)
- minitech 8y agoUse secrets.choice instead of random.choice, since only the former is backed by a CSPRNG.
- aepiepaey 8y agoOr random.SytemRandom().choice if the secrets module is not available.
- raverbashing 8y agoYou can always open /dev/random and read bytes from there as well
- garethrees 8y agoThis one-line shell script is a bit simpler: base64 /dev/urandom | head -c 16 (Vary the number of characters according to the desired entropy: you get 6 bits of entropy for each character of output, so 16*6 = 96 bits in the example. Use /dev/random or /dev/arandom if you prefer those random sources.) For passphrases, use GNU shuf (from the coreutils package): shuf -n 4 --random-source=/dev/urandom /usr/share/dict/words
- mistaken 8y agoAlso `openssl rand -hex 16` works pretty well :)
- sametmax 8y agoEven if one can just use `pwgen` on most linux plateforms, it's a fun exercice, and one that is always welcome in classrooms. You need to parse the cmd, make sure you use the proper random generator, and accumulate different source of characters. Options such as --allow-unicode, --exclude-similar-chars or --group-chars all provide small additional challenges in different areas. It's something all students should code at least once, if not for pleasure, at least for practice. But honestly I find it fun enough that I just wrote one again after reading the article. I'm pretty sure a timeline of all the attempts is telling of ones progression in style :)
- raverbashing 8y agoHere's my biggest pet peeve when using password generators: passwords containing special symbols like (but not limited to) "-\/({^$:%" will just break in some random service and you'll stay a long time trying to escape them in the correct way until they work Keep your sanity and avoid special characters.
- giancarlostoro 8y agoI only run into banks hating those, and obscure websites I am pretty sure I don't bother going back to. I don't understand why they're such an issue, but now I have less keys for a hacker to guess.
- raverbashing 8y agoTry setting it on an URL, on an environment variable or in a config file.
- giancarlostoro 8y agoWhy would you ever put a password on a URL though? That's really bad security. I understand what you mean, but passwords should be stored in some hashed / encrypted form.
- darkpuma 8y agoI appreciate the follow through of showing how the package is set up. That's something a lot of articles or blog posts on racket seem to miss.
- oddthink 8y agoIs that nested-define common racket style? I know it's been legal, at least since R4RS, but I've never seen it actually done.
- widdershins 8y agoNot sure if it's common amongst Racketeers, but I've used it a few times in R6RS Scheme. It can help reduce nesting in complicated functions. But in these simple cases I think most would reach first for `let`.
- soegaard 8y agoYes, you can see the style guide here. https://docs.racket-lang.org/style/Choosing_the_Right_Construct.html#%28part._.Definitions%29 https://docs.racket-lang.org/style/Choosing_the_Right_Constr... The reasoning is that `define` doesn't increate horisontal indentation.
- Nasreddin_Hodja 8y agoI wrote in bash for myself: https://github.com/rekcufniarb/pswrd https://github.com/rekcufniarb/pswrd (it also outputs a random password if called with -r arg)