6 ms·
I agree with you, but I actually used the brute force for data recovery. I had a NAS with a 22 characters passphrase that I had up and running for years and ev
by polack 7y ago
I agree with you, but I actually used the brute force for data recovery.
I had a NAS with a 22 characters passphrase that I had up and running for years and eventually forgot the password to. When I set it up I practiced the password enough times that I was sure I would never forget it so I never stored it anywhere. After years of never rebooting the NAS parts of the passphrase eventually got blurry and when I was about to move I realized I couldn't remember it anymore.
I didn't really have anything of high value stored on it, but it kind of became a pet project to try to "crack" into it again. Together with Hashcat and the extracted header I eventually managed to brute force it after a couple of weeks :)
- CaptainMarvel 7y agoHow did you brute force 22 characters? Did you somehow use your fuzzy memory of the password to help?
- polack 7y agoYes, sorry I was unclear about that. I knew multiple parts of it, but not what position the segments would go into. I had also mixed the passphrase up with another old obsolete one, so I had too many of these segments (back then I broke up the passphrases into blocks of 4 chars in my head) to fit in. There was also a couple of chars that I was uncertain about so those got "fully" brute forced. The worst part about the process was that it was hard to create rules for Hashcat to generate all different possibilities for the passphrase with all the information I knew about it baked in.
- MawKKe 7y agoSo.. nothing to do with LUKS?
- lucb1e 7y agoJust because luks isn't bad doesn't mean you can't use cracking tools to recover data when you forgot half the password, only have surveillance footage of the password being typed, have a bad password, etc. Since the article doesn't document any (new) luks weaknesses, none of the comments will be about luks being insecure.
- MayeulC 7y agoI've been in the same situation multiple times. I don't recall a case where the data was of critical importance, so I could get away with it, but using the parts of the passphrase I knew in a combined bruteforce/dictionary attack definitely crossed my mind. Do you have some links to reference material on how to achieve that?
- DyslexicAtheist 7y agoone way to solve the problem of memorizing (long passwords) is to use something like this: to avoid forgetting it use a string of words that make sense to your brain[1] but are unlikely to be encountered in the wild (in any texts). Example passphrase: "My hamster kicks soapy homework with smurf locks like a tandem at 45 o clock!" Then use this to generate a hash which can never be remembered in itself, and is unlikely to be brute-forced: $ echo -n "My hamster kicks soapy homework with smurf locks like a tandem at 45 o clock!" | sha512sum 7364796a1ad957d7c524165aa2fec2501eaa59e6bd8380bad3252504cdb8592018e30ae2fff1b2c2295e6da7a7f47f52ef1c0e3010c054598d76fe0c6d64bac6 - this way there is no need to remember the hash itself as long as you know how to recreate the hash (+ have the tooling present like sha512sum). In case you want to change the hash without having to remember a new passphrase just twiddle with the input string (by changing one character only) to get a totally new hash. If you're on a multi-tenant machine this is probably dangerous since running `ps` might show other users on the system the input string when you run the command. Not an issue with single user systems. In case you want to avoid the command being recorded in your shell history file you can prefix the whole command with a blank (space). Benefit of this is you get a pretty long hash that is impossible to brute-force and extremely hard to remember, which makes it really useful as a master-password.
- Thorrez 7y agoOne weakness of this is that sha512sum is a fast hash, ideally it would use a slow and memory hard-hash. Of course if your password is strong enough it doesn't matter. An example attack would be an attacker compromises the password database of a site you use, and that site doesn't hash passwords. Next the attacker cracks that hash, which requires your password to be somewhat weak, but is aided by you not using a slow hash. Next the attacker uses that cracked master password variation to crack your LUKS setup. While LUKS uses a slow memory-hard hash, the attacker doesn't need to do many attempts, because the password is a small variation of the password the attacker already knows.
- zaarn 7y agoThat would matter less if you use the hash as a password as the comment suggests; in that case it matters what the website below in the stack uses.