5 ms·
Seems to be a number of assumptions: a) the words are correctly spelled b) you're only using words from macOS's /usr/share/dict/words c) there no more than 4
by ehmish 7y ago
Seems to be a number of assumptions:
a) the words are correctly spelled
b) you're only using words from macOS's /usr/share/dict/words
c) there no more than 4 words
d) there's no punctuation, capitalisation or spaces
Which together produce the relatively low cracking time, and given that you generally can't know any of those things a priori you can't assume them when cracking a password
Edit: As was pointed out, it's strictly having more than 4 words that helps the most with increasing entropy, whereas allowing less than 4 words in the problem space is mostly a rounding error.
- slooonz 7y ago> c) there are exactly 4 words Going from "4 words" to "4 words or less" is absolutely negligible for sufficiently large words list. For example, if you take a dictionary of just 3000 words, then "4 words" is 46.20299 bits of entropy while "4 words or less" is 46.20346 bits of entropy. The larger the dictionary, the worse the effect becomes.
- ehmish 7y agoRight but if there's 6 words it goes up exponentially, even if they're short words >>> math.factorial(4) 24 >>> math.factorial(6) 720 So the password iamahorsebatterystaple is about 30x harder to crack than correcthorsebatterystaple using this approach, and I highly doubt people doing xkcd passwords are strictly sticking to 4 words
- slooonz 7y ago> So the password iamahorsebatterystaple is about 30x harder to crack than correcthorsebatterystaple using this approach You are massively underselling it. It’s n² harder with n being the number of words in your dictionary. (except that "iam" is certainly not two random words) But my point was that varying the number of words virtually doesn't add security — the security of this scheme is defined by the number of words in the dictionary, and the maximum number of words you’re willing to remember. Whether that maximum means "pick MAX words" or "pick at most MAX words" has no real impact.
- yabadabadoes 7y agoYeah though grammatical constructs are IMO breaking the rules and their frequency of use would probably be added to the dictionary as compounds, iama, youarea, thereis, .. are all more practical in a cracking dictionary than a few more 18th century salon talk words, etc.
- ehmish 7y agoWhat's more difficult to add to the dictionary before hand are things more like "samisacorrecthorsebatterystaple". Once you add in proper nouns, the practicality of pre-loading compounds doesn't work as well, since there's so many proper nouns. Plus proper nouns are often more memorable because they have meaning to the person who wrote the password.
- yabadabadoes 7y agoIf I were building a dictionary I would simply do an analysis with no punctuation of media to get frequent compound strands, brands, names, etc.. Common names, etc would IMO be very frequent compared to a foreign loan word, like samovar. So once the rules are lax for password choice, the crack patterns are again julieisborninjuly or what not and the weak users are back in a very small search space.
- trehalose 7y agoJust to be pedantic: That's going up superexponentially.