5 ms·
This may help answer your question about the inflection point: http://www.baekdal.com/tips/password-security-usability http://www.baekdal.com/tips/password-secu
by biturd 15y ago
This may help answer your question about the inflection point: http://www.baekdal.com/tips/password-security-usability http://www.baekdal.com/tips/password-security-usability
It is a bit old, but not so old that you can't determine what a good length is. More importantly, it is not always about the length, where something like "alpine fun" (two common words) may take a couple months, but just adding in "this is fun" (three common words) gains you thousands of years in time.
Before reading, I was under the impression that without a password manager, it has become impossible to secure passwords by memory as GPU's became more powerful. My impression was that "random", alpha-numeric, plus non-alpha-numeric characters, and, of great length would be needed.
This article leads me to believe otherwise, and that something like "this#is#my#password" should be sufficiently uncompromisable for some time to come. It is also highly rememberable to me.
There was a youtube video linked, I believe from HN, apx. 3 weeks ago, that showed a demo of GPU password cracking that was a bit more illustrative than this article, and more current. Unfortunately, I can't seem to locate it.
- andrewcooke 15y ago1 - the article linked here on hn gives 9 characters as the current practical limit for brute force hacking with a 100 values per character (upper + lower + symbol). the link you gave calls 6 characters "safe for life" when using alphanumeric + symbols. while exactly what symbols are included is significant, there's clearly a major discrepancy (i guess that the problem is two-fold: your link is woefully out of date and the link here is over-estimating rates on gpus). 2 - also, using more words is, in the context of the article you linked to, related to dictionary attacks. and again your article is pretty poor since it's giving an example with very common words which implies that a very small dictionary would be needed. i would not call "this is fun" a safe password. 3 - the article you link to is again misleading in that it completely ignores password helpers and puts too much emphasis on local restrictions like reducing login rates. it seems like it was written before both the web (we are seeing lists of passwords being stolen - that makes "restricting retries" completely irrelevant) and gpus were common. i would not use it as a reliable source of advice.
- bonzoesc 15y ago> Before reading, I was under the impression that without a password manager, it has become impossible to secure passwords by memory as GPU's became more powerful. My impression was that "random", alpha-numeric, plus non-alpha-numeric characters, and, of great length would be needed. Remember that the article is about today's state-of-the-art. Next year, cracking algorithms might be better, GPUs will certainly be better, EC2 spot instances might be cheaper, and dictionary guessing algorithms will be smarter. A 50-character random password loaded with symbols, digits, and letters is good in the face of that.
- dkokelley 15y agoI really wonder how dictionary attacks will progress as word frequency and distribution is studied. "this is fun" has 11 characters, which has 310^15 possible lower-case combinations, and (using the 500,000 word dictionary), has 1.2510^17 combinations, an order of magnitude more. But, assuming a smart hash cracker, the size of the dictionary could be shrunk considerably. I believe most people use approximately 10,000 common English words (not including proper nouns or fictional words). 'this', 'is', and 'fun' would all show up under that scheme. Using a 10,000 word dictionary, there are only 1*10^12 combinations. Much less secure than an 11 character random password. A smarter cracker could apply sentence structure rules to skip odd, fragmented sentences (ie. "dog foot with happy"). Also, the article failed to mention the risks of compromised password databases. Sure, the attacker could just gain access to the actual files he or she wants while bypassing the login step, but the list of username/email and password credentials are a major threat to users. Most users only have a handful of passwords, and an attacker could leverage the one they know to find the ones they don't. Password managers are necessary for this reason, to provide unique passwords to each protected site. If password managers become wide spread, then why not let them remember arbitrarily long and complex passwords. It can't hurt, right?