4 ms·
This perpetuates the fundamental misunderstanding on what makes passwords strong. In fact, no password itself has any guaranteed entropy and hence strength- onl
by Straw 6y ago
This perpetuates the fundamental misunderstanding on what makes passwords strong. In fact, no password itself has any guaranteed entropy and hence strength- only a distribution has this property. Since humans provide such poor randomness, we should never pick passwords at all, but generate them.
Research should go to making more memorable generated passwords, looking for the best tradeoff between that and entropy.
- nmca 6y agoI had a (slightly silly) go at tackling this problem via a secure mapping and language-model reranking according to probability of text under urban dictionary - there is a detailed description here if you're curious: (pdf-link) https://n-mca.github.io/work/Nat_McAleese_Arbitrary_Encodings.pdf https://n-mca.github.io/work/Nat_McAleese_Arbitrary_Encoding...
- FabHK 6y agoThat fundamental misunderstanding is not a misunderstanding. You can look at individual passwords and estimate their "entropy", such as zxcvbn does, and in fact you need to. Because the distribution that matters is not the one you used to pick the password, but the one that the attacker uses. You could pick from the universe of arbitrary UTF-8 strings of up to 1000 characters (huge entropy), and pull "password" - but that would be a bad password, despite the distribution. Or you could pick randomly from {"password", "09854yngbmoujcr08twnvgje8w6g7bkv,cmxm5^&*9NMF"}, and pick the latter, and it would be a reasonable password, despite carrying only 1 bit of information in the given distribution. > Research should go to making more memorable generated passwords, looking for the best tradeoff between that and entropy. Agreed on that.
- Straw 6y agoAlthough by chance you might pick a good password, you have absolutely no guarantee of the strength unless its generated from a distribution with known entropy. The problem with assuming any particular distribution for the attackers is that they tend to constantly update their attacks as password trends evolve. Random password, picked uniformly from strings up to 1000 characters? Almost certainly at least 900 characters, extremely strong. Probability of picking "password"? Less than the probability you're currently hallucinating, or that there's a bug in your code, or that an attacker guesses your password by pure chance. You can't show that particular string isn't easy to guess- perhaps it follows a common pattern of humans spamming "random" keypresses with far lower entropy than one would expect. Can I show that I could guess something without seeing it beforehand? Probably not. Don't settle for "I couldn't guess this password" when you can get "No one can guess this password".