3 ms·
The final section of the article about ‘password diversity’[0] is interesting to me; allow me to think aloud for a little bit. Whilst I appreciate the recent s
by DicIfTEx 5y ago
The final section of the article about ‘password diversity’[0] is interesting to me; allow me to think aloud for a little bit.
Whilst I appreciate the recent shift to advising passphrases (and password managers, but that's a different topic) for normal users, the I've noticed that received wisdom tends to be that the words need to be unrelated, i.e. don't use a quote from a book (although I notice that the NCSC's own guidance[1] does not state this).
However, surely this would be an acceptable workaround for those who would struggle to remember (or, as you say, conjure up) an assortment of random, sufficiently-complex words? Password diversity would be enhanced if the text-based authentication ecosystem included traditional passwords, random passphrases AND semantically-meaningful sentences, more so than with only the first two?
Of course, quotations have their own strength problems (i.e., in a language like English any sentence will contain a lot of 1–3-letter words), and perhaps ‘it was the best of times it was the worst of times’ would just become the new ‘123456’, but perhaps the ecosystem-wide strengthening effect could mitigate those?
[0] https://www.ncsc.gov.uk/blog-post/the-logic-behind-three-random-words#section_4 https://www.ncsc.gov.uk/blog-post/the-logic-behind-three-ran...
[1] https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/use-a-strong-and-separate-password-for-email https://www.ncsc.gov.uk/collection/top-tips-for-staying-secu...
- tgv 5y agoHow many users actually read? I don't trust the surveys on this, at all. But if they've read a book, many a passphrase will be "you're a wizard", or some other YA cliche. In book quotes, there will be extremely little diversity. And nobody is going to type 'it was ...', as long as 'hunter1234' suffices. I don't think this is a problem with an easy solution. The low hanging fruit, enforced password rules, has been tried, further strengthening requires alternative solutions, such as 2FA, hardware keys, one-time pads, etc.
- DicIfTEx 5y agoExpanding on this, is it possible to quantify the effect on entropy of the words in a passphrase being semantically related rather than randomly-chosen? Without being a cryptographer/statistician, my gut feeling is it would involve Markov chains somehow.