19 ms·
Xkcd Password Generator
- ck2 15y agoI've been doing this for years on sites that allow long passwords - "pass sentences" - but I also throw in a number or two.
- buro9 15y agoI've also been doing this for years, but with bits of my post code thrown in to fulfil those edqe cases where complexity requirements are needed.
- jwingy 15y ago+1 (TM now I guess) You could have four word phrases that are maybe only ~12 characters, which if there are only alphabetical characters in the password, are still very much crackable via GPU brute force (http://mytechencounters.wordpress.com/2011/04/03/gpu-password-cracking-crack-a-windows-password-using-a-graphic-card/ http://mytechencounters.wordpress.com/2011/04/03/gpu-passwor...)
- mrspeaker 15y agoHe he, reminds me of the password generator I made concatenating 3 words from the list of the "500 most common passwords": http://www.mrspeaker.net/2009/01/09/make-secure-passwords/ http://www.mrspeaker.net/2009/01/09/make-secure-passwords/ The top 500 list has an awful lot of naughty words - so the phrases are pretty easy to remember ;)
- adnam 15y agoSuch a password scheme provides much less than 44 "bits" of entropy. Considering the use of 4 randomly chosen words from the c.170000 english words in general use, means we can guess the paraphrase in around 2^22 tries - even less than "Tr0ub4d0r3&". EDIT: I'm totally wrong, it's more like 2*10^22 ... oops!
- TetOn 15y agoWouldn't you first have to know that the passphrase consists of four randomly chosen words (eg not three, five, or eight)? To me, that's the underlying strength of the approach that the comic (!) is trying to highlight.
- burgerbrain 15y agoThe entropy is actually calculated with the assumption that the attacker already knows those things. If they don't, then it is higher.
- meentsbk 15y agoThere is a really interesting discussion on using passphrases from stackexchange that is probably worth linking: http://security.stackexchange.com/questions/6095/xkcd-936-short-complex-password-or-long-dictionary-passphrase http://security.stackexchange.com/questions/6095/xkcd-936-sh...
- burgerbrain 15y agoThere is no need for scare quotes around bits. The term is being used in a technically correct fashion. https://secure.wikimedia.org/wikipedia/en/wiki/Bit#Information_capacity_and_information_content https://secure.wikimedia.org/wikipedia/en/wiki/Bit#Informati...
- adnam 15y agoErr, yes thanks. I was trying to emphasise the fact that the multiplier of entropy is not the "bit", but the "word" (in the linguistic, rather than the computer architecture sense)
- ErrantX 15y agoNot a good idea, sadly. In fact I'd go so far to say this is a really bad suggestion; because it gives a false sense of security. There is potentially a lot less entropy in this password than "Tr0ub4d0r&3", assuming the hacker is smart enough to realise he can trivially test combinations of dictionary words in very short amount of time. (EDIT: I'm way out of touch with this; it's not as trivial as perhaps I figured. See lower in the thread) However; it is in the right direction - introducing some sort of extra entropy can invalidate that form of attack and make this as secure as XKCD suggests. What do I currently do? I take a reasonable length common word, do a string/number replacement as so: H4ck3r N3ws And then repeat it 3 or 4 times: H4ck3r N3ws H4ck3r N3ws H4ck3r N3ws H4ck3r N3ws For extra entropy mix it up: H4ck3r N3ws H4ck3r News H4cker News Hacker News That's a simple example - so long as you have a reasonably random scheme then it is not easy to test against, but is fairly simple to remember. Bingo :) (EDIT: for the down voter(s) note: XKCD specifically says random common words - obscure words are another matter)
- darklajid 15y ago> he can trivially test combinations of dictionary words in very short amount of time. Explain the reasoning behind this, please. Start with: You don't know the dictionary I used, but have to use one that seems 'good enough' (i.e. a superset of mine, if possible). How many words are in there? How many combinations can you create for 'two word phrases'? (You don't know the length of my phrase) How many for three? How many for four words?
- hesselink 15y agoThe XKCD criticism of the 'bad' password has the same problems. How does the hacker know I have this kind of password (starting with a real english word, for example)?
- darklajid 15y agoNo, it doesn't have the same problem. It criticizes a particular way to choose passwords, leading to a result that seems 'secure' and even quite good to lots of people. One that easily satisfies braindead corporate password rules. The entropy given there is based on that way to choose a password and even explained, graphically. If you choose your password totally different and from different sets of characters, then the number will be off. That's not a surprise though?
- pilif 15y agoAssuming that this method for generating passwords gets popular enough, brute force tools will begin to create an optimized attack for these passwords. As there are so little words available, if I were to write a brute-forcing tool, I would try combinations of four words in my wordlist once I failed with my one-word-dictionary attack before I start trying out all characters. But all is not lost: Either use more words or vary the amount of spaces you put between words. This way the dumb optimization "try four words delimited by space" wouldn't work on your password and they would have to go over to plain old brute forcing at which point, I agree, the longer, the better.
- burgerbrain 15y agohttps://secure.wikimedia.org/wikipedia/en/wiki/Diceware https://secure.wikimedia.org/wikipedia/en/wiki/Diceware Properly executed, this will protect you against brute force attacks. No need to do nonsense like adding more spaces. Of course XKCD botched it and said an inadequate minimum length... Notable quote from the article: "This level of unpredictability assumes that a potential attacker knows both that Diceware has been used to generate the passphrase, the particular word list used, and exactly how many words make up the passphrase."
- darklajid 15y agoWas just about to quote that to you. Don't you think that you should take this quote into account when you say xkcd botched it?
- burgerbrain 15y agoThat's not how people in crypto roll :) He calculated the entropy assuming that knowledge was had, I think he botched it in saying that 44 bits were enough. Of course if he were to recalculate it without those assumptions, but make it clear that he were doing that, then it would be better.
- ordinary 15y agoEven 4 words is good enough for many use cases.
- iaskwhy 15y agoI always thought using two password fields with simple words would be much harder to break than one field only (which can be used to really strange passwords but also for simples ones as we all know). Someone care to calculate how much it would take to break it?
- corin_ 15y agoWell it depends how it's stored, but assuming a fairly standard setup it wouldn't particularly help. The main issue with website security isn't people brute forcing the website login box, it's people cracking the hashes after stealing them. So if you had two easy to crack hashes stored in the database, you crack them both and off you go.
- iaskwhy 15y agoOh, I was (like the article) assuming you would concatenate both words (add a space or something else in between if you want) and it would be all stored in just one field. What about it?
- jsulak 15y agoI prefer using a program like Password Safe (http://passwordsafe.sourceforge.net/ http://passwordsafe.sourceforge.net/), and use a safe password that's a long sentence (with punctuation). Then I can use arbitrarily long and complex passwords for all my accounts, and not have to worry about memorizing them individually. The password safe can even be synced across computers using Dropbox.
- nollidge 15y agoI prefer KeePass simply because it's got implementations on multiple OSs, as does Dropbox (to sync the password database file). So I've got it on my iMac, Android phone, Windows laptop, and Windows work PC.
- mtogo 15y agoIf you have an iPhone or don't want to use keepassx, you can use an online password manager like Passpack or Lastpass. The downside is that you need to really trust the password manager, as they have all of your usernames and password.
- shinratdr 15y ago1Password supports all those devices as well.
- zobzu 15y agoI prefer using a digital key that's always going to beat the entropy of the memorable passwords
- dredmorbius 15y agoGPG-encrypted free-form file (though it's fairly structured), edited via vim and a well-known "auto-encrypt/decrypt GPG files" configuration: http://vim.wikia.com/wiki/Encryption http://vim.wikia.com/wiki/Encryption (Actually, from that page, vim now has built-in blowfish encryption, which I'll have to look at -- yet another argument in favor of sharing tips on the 'TarTubes: you may learn something even when you're sharing your own knowledge).
- ZoFreX 15y agoI would actually advise going against this advice. While it isn't a best practice, password sharing can and does happen, as does shoulder-surfing. It would take a LOT of effort to memorise my password, but a simple four word password will probably be remembered by accident. In a year's time if I piss a friend off, I don't want my Facebook password to be readily accessible in their memory. I think more people need to learn to remember arbitrary strings. There really is no way around that problem if you want a decently secure password, and it's rare someone has a "good memory" - in most cases they've just learnt how to remember things well. (Note: This doesn't really apply to me or most of us here in most cases, but for example my WiFi password is of the form "Mycatsname9" and yet my neighbour still has to ask me for it whenever her phone forgets it)
- darklajid 15y agoHow do you share your preferred password? Because I guess everything but sending it per text/mail would be tedious, while it would work better with a couple of words. Shoulder surfing: It's certainly a risk, but I'd say that prolonged shoulder surfing shouldn't be possible. If I type fast, it will be very hard to make out the phrase. If I type slow, you cannot stand around that long. And - I'm not a security expert, but how much do you gain if you saw a couple of chars here? My intuition (yeah, shouldn't trust that) says that it's worse if I watch you and know the _first_ character of your password than you seeing the first 1-3 characters of the first word of my passphrase? (We don't know the name of your cat, so judging the quality of the password or your neighbo(u)r's ability to remember it is hard)
- ZoFreX 15y ago> And - I'm not a security expert, but how much do you gain if you saw a couple of chars here? My intuition (yeah, shouldn't trust that) says that it's worse if I watch you and know the _first_ character of your password than you seeing the first 1-3 characters of the first word of my passphrase? Novel thought and possibly worth persuing, I hadn't thought of that. I want to re-iterate this isn't something I broadly apply across all my passwords or even many of them, just that for some users password sharing is a use-case.
- 15y ago
- nakkiel 15y agoThis might come in handy: shuf -n4 /usr/share/dict/words | tr '\n' ' '
- eru 15y agoIf you allow multiple occurrences of the same word, you can get slightly higher entropy while making the passwords potentially even easier to remember. echo $(for i in 1 2 3 4; do shuf -n1 /usr/share/dict/words; done) (Sorry, I'm not very good at bash, so this loop is probably not idiomatic.)
- DufusM 15y agoI don't think those words are very practical. For example, 4 consecutive runs produced: shippon preannouncer half-hourly withgang egotize baffs chapter monolater photoengraver beachhead linguidental autoheader hazeled defloration exhumate barretries none of which seem particularly easy to remember (or spell even).
- nakkiel 15y agoIt's like with any other program supposed to help you picking up a password; you run it a couple of times until you find something that ticks. Beirut ejecting sidings mourns
- ddlatham 15y agoA lot of comments here seem to be missing the point. The main point is to use passwords that give you the most "bang for the buck" in the sense of adding the most bits of entropy for the least difficulty of remembering. Adding an extra number, or punctuation, or certain numbers of repetitions generally adds only a little bit of entropy for a significant cost in additional challenge to your memory. Our minds are well suited to remembering combinations of common words, and by stringing a few such words together, you can generate a larger search space than using a single word with a few substitutions. Even if the attacker knows the scheme you're using, he still must search through the space of combinations of common words, which XKCD is pointing out is quite large.
- zobzu 15y ago171K words in the english language 4 words no spaces 171k^4 vs 255^8 for a 8 char pass
- drcode 15y agoIncorrect: It's 171k^4 and 255^8. (which works out to 8.55E20 and 1.78E19)
- kijinbear 15y agoActually, since you normally can't use anything but characters in the 0x20-0x7E range, the 8 char password has much less entropy: 95^8 ~= 6.63E15. I love the backtick in my passwords. If a website accepts it and doesn't give me any issues, it's a decent indicator of basic security.
- y0ghur7_xxx 15y agoReminds me of this previous discussion: http://news.ycombinator.com/item?id=2450972 http://news.ycombinator.com/item?id=2450972 Maybe Randall was inspired by that post.
- kahawe 15y agoOriginal xkcd link: http://xkcd.com/936/ http://xkcd.com/936/ Oh and there are unfortunately way too many systems limiting your password to only 6 or 8 characters still in use today.
- hm2k 15y agoWhat about sites that don't allow spaces? I know hotukdeals.com only allows [a-zA-Z0-9] which sucks.
- wisty 15y agoAnd also, sites that have a limit on password length. And sites that have a silent limit on password length, and secretly truncate it. And sites that have different truncation, depending on which form you use. And sites that require a Capitals, lowercase, and numbers, because nobody would just use name+birthday.
- pavel_lishin 15y agoLeave the spaces out..?
- duck 15y agoExactly, or if the site requires numbers/symbols those three spots are perfect place to put those instead of spaces.
- hm2k 15y agoThat's not what is proposed here though. The point is that one size does not fit all at the moment. I guess developers need to change the way they handle passwords.
- wisty 15y agoHow about (NOT SECURE YET, IT NEEDS MORE ENTROPY): from nltk.corpus import wordnet as wn all_animals = set() def add_to_set(animal): all_animals.add(animal.name.split('.')[0].replace('_',' ')) for child in animal.hyponyms(): add_to_set(child) add_to_set(wn.synset('animal.n.01')) all_animals = list(all_animals) actions = ['ate','chased','killed','fought','kissed', 'talked to','hated','loved','ambushed','fled'] # can add more def make_password(): import random random = random.SystemRandom() # is this secure? choice = random.choice return 'the %s %s the %s'%(choice(all_animals), choice(actions), choice(all_animals)) If you pruned out 90% of the animals (i.e. the obscure, hard to spell, or scientific names), this is still about 20 bits. And the passwords are kind of memorable (I've gotten such gems as "the dodo chased the guppy" or "the tigress killed the king charles spanial"). You could also add a humorous adjective ("rabid", "talking", "magic", "invisible", "evil" ...) or adverb ("roughly", "quickly", "quietly", "secretly" ...). You could also add a place name.
- Periodic 15y agoCompletely random strings of words can be hard for me to remember, but something like, "the {adjective1} {animal1} {verb} the {ajective2} {verb2}" would be much easier for me to remember because the words relate to each other ways I already understand. I expect we can get some fairly high entropy from just simple schemes like this. However, the length of the password can be a real pain if you have to type it often, even once a day.
- wisty 15y agoYou could get about 8 bits per animal, and 5 bits per hand-written verb / adjective / place (32 choices per category). So that's about 7-10 words you need in the frame. You could get decent entropy with: the {adj} {adj} {animal} {verbed} the {adj} {adj} {animal} from in {place}. That's 5+5+8+5+5+8+5 = 41 bits. I'm just wondering if it's worth it.
- kragen 15y agoThis is truly awesome. You could easily use a more complicated grammar, but it might get tricky to generate a password with a specified amount of entropy.
- nmcfarl 15y agoI've been using phrases and sentences as passwords for a while, and I've found that there are 2 main problems; 1) A lot of sites, still in this day and age, have max password lengths, so I still have a lot of short passwords. Usually this is bank sites and the like. 2) Password entry fields are often very short visually, and with a long password getting lost is much easier. I find I have to type them over A LOT. The second is actually the more annoying problem.
- colanderman 15y agoDon't forget sites that require: "your password MUST contain at least one number, one uppercase letter, and one of the following characters: !, @, #, or $, but not %, ^, &, or *". I slap my forehead at how counterproductive these requirements are.
- Simucal 15y agoWhat could the reasoning behind those requirements possibly be?
- eru 15y agoCovering your ass by disallowing passwords like "password".
- Simucal 15y agoNo, I meant specifically why they would allow certain special characters and not others.
- rmc 15y agoThose requirements are there for the people who try putting just their name or "password" or their 4 digit ATM PIN as their password. For very short passwords, only having alphabetical (not even alphanumeric) passwords is terrible. Those requirements are there to prevent some really stupid passwords.
- 15y ago
- drcode 15y agoOne slight addition to the xkcd password scheme that would add another order of magnitude of security would be to have your own personal "salt" that you add to all your passphrases. In this case, the salt would be a short, traditional, hard to remember password that you re-use with every xkcd style password. It would be hard to remember, but you'd only need to memorize it once. So if your personal salt is "@T#23a" you would use "@T#23a correct horse battery staple" on one website and "@T#23a giant bug transistor leech" on another website.
- cdavidcash 15y agoYou might want to read the cartoon again to see why this is useless, counterproductive advice.
- dsmithn 15y agoIf this kind of thing takes off, it will become easier for dictionary based password attacks. Using this advice would go a long way towards preventing this.
- AdamTReineke 15y agoEasier, yes, but not easy. A dictionary attack on 4 words is the same as brute forcing 4 letters except now instead of just 26 letters there are thousands. 2000^4 vs 26^4 = 35,000,000% more to check.
- xyzzyb 15y agoYes, but the salt could also be useful for sites that require passwords to include a number, a non alphanumeric character, etc.
- re_todd 15y agoThat is what I do, I have a 4 character personal salt, like "7Pd$", and put it in the middle of a lowercase word or phrase. Having a symbol, lowercase letter, uppercase number, and number will satisfy most password requirements. I use it on many sites, so it is easy to remember. It also makes it simple to write passwords down, e.g. "correct horse ^ battery staple" which means to me "correct horse 7Pd$ battery staple", but would not be useful to someone who saw it, since they don't know my personal salt. A combination of what xkcd said and a short personal salt that's easy to remember is probably best.
- nrbafna 15y ago"For those of us pedantic enough to want a rule, here it is: The preferred form is "xkcd", all lower-case. In formal contexts where a lowercase word shouldn't start a sentence, 'XKCD' is an okay alternative. 'Xkcd' is frowned upon."
- deleted 15y ago[deleted]
- scythe 15y agoYou could probably get a few more bits of entropy kind of easily if you use words from other languages. This doesn't help the monolingual among us but it's great for me.
- kijinbear 15y agoSome Koreans do this: they just type up some Korean words. Since most password fields only accept ASCII symbols, the password gets entered as a nonsensical string of alphabets. For example, the Korean word '비밀번호' (meaning 'password'), when typed on a standard Korean keyboard, becomes 'qlalfqjsgh'.
- eru 15y agoYes, though the number of additional bits you get from increasing the size of the dictionary decreases fast. E.g. suppose English and German have the same number of words, then using both only gives you one more bit per word. (Actually, slightly less since some words exist in both languages. Like `hell'.)
- scythe 15y ago>Yes, though the number of additional bits you get from increasing the size of the dictionary decreases fast. Well, sure -- but once you're at around two or three languages, you get to imagine that the attacker doesn't know what languages you're using. If I use English, Japanese, and Spanish, I can figure on the attacker needing to check the Germanic (English, Dutch, German), Romance (Spanish, French, Italian), and Asian (Japanese, Chinese, Korean) languages at a minimum. Jargon helps too, and proper names. "dijkstra bicycle entonces boojum daihinmin"
- eru 15y agoAlways assume the attacker knows your scheme, but not your random bits.
- deleted 15y ago[deleted]
- Gullanian 15y agoOnce hackers realise people are using ~4 random words for a password the entropy will decrease hugely.
- wcoenen 15y agoI think you've got it backwards: the entropy calculation here assumes that the attacker already knows the scheme. The 2^44 possible passwords are therefore a lower boundary for the entropy. In practice the attacker must cast a wider net because he doesn't know exactly which word list you use, or if you are using a completely different password scheme. This increases the difficulty.
- tantalor 15y agoSorry, but this isn't novel. I can't find it now, but I read a blog post that described this technique recently (~6 months ago). Edit: y0ghur7_xxx (http://news.ycombinator.com/item?id=2872827 http://news.ycombinator.com/item?id=2872827) found it: http://www.baekdal.com/tips/password-security-usability http://www.baekdal.com/tips/password-security-usability
- Symmetry 15y agoI generally use gpw to generate long random but pronounceable passwords. Something like 'armsdaynistoppo' is fairly entropic, easy enough to remember, and when I'm used to it I can type it much faster than 4 random words.
- IgorPartola 15y agoPut this in your .bashrc: function rpass() { strings /dev/urandom | grep -o '[[:alnum:]\/!@#$%^&*()<>,.,{}]' | head -n $1 | tr -d '\n'; echo } Then run $ rpass 16 and get a 16 character random password with a fairly high entropy. Then just use a service like LastPass or a solution like KeePassX or even a single GPG-encrypted file to store your passwords. Problem solved. Passwords are evil. Most of them should be treated the way you'd treat your private SSH or SSL key. Whenever you can eliminate a password and get the user to authenticate using a third-party identity provider, you are doing them a favor. Edit: with 80 possible characters, you get 80^16 possible passwords: 10^19 years at 1000 guesses/second.
- yuvadam 15y agoActually LastPass has this option built-in. It can generate a strong password in-form and directly save it to your password vault. Very useful.
- IgorPartola 15y agoYes, but I prefer to generate the passwords on my own. I also use this to generate random passwords for root accounts (sudo FTW), etc.
- duck 15y agoIf you use KeePass there is no need for the script since it will generate one for you based on rules you can set.
- slug 15y agoor use pwgen , apg, etc
- parfe 15y ago1000? Try 600 million passwords a second. http://www.elcomsoft.com/lhc.html http://www.elcomsoft.com/lhc.html
- IgorPartola 15y ago
- dendory 15y agoIf you look at the source, their word list contains around 1600 words. That is just no where near enough. Using this would give you a very easy to crack password. You need to make up your own passwords with words you come up with.
- eru 15y ago> You need to make up your own passwords with words you come up with. That might have even less entropy. Why not just get a bigger dictionary? Most Unix systems even come with a dictionary.
- kragen 15y ago1600 words is 10.6 bits per word. If you want to reach 70 bits (safe from offline attacks with custom hardware), that means you need 7 words, which is within most people's capacity to memorize. If you increase your wordlist to 65536 words, you can get 16 bits per word, but you have to include words like "lefeuvre", "aarau", and "aubagne". Then you can reach 70 bits in only 5 words. That's not worth it. Inventing your own words is unlikely to produce very random words. You'll probably mostly invent the same few hundred nonsense words that any other speaker of your native language would invent. In other words, you have no idea what you are talking about and should not have posted.
- salvadors 15y agoOn what basis is that "very easy"? Four words from 1600 is 1600^4 permutations, which would take over 200 years to test at a 1000/second attack. Sure, if we're talking about a different type of password, and 2-billion-tries-per-second attacks, it'll fall in about an hour, but simply pushing that out to six words from that dictionary will still stymie that level of attack for a couple of hundred years. The size of the dictionary is much less important than the length of phrase you generate from it.
- nikcub 15y agoas a bash alias: word_pass() { cat /usr/share/dict/words | awk 'BEGIN{srand();}{print rand()"\t"$0}' | sort -k1 -n | cut -f2 | head -n 4 | tr "\\n" " " && echo } then: $ word_pass corticifugally tetraploidy democrat vibrionic (if you notice how this works, you can see that it isn't super-efficient, but it works)
- adr_ 15y agoUsing shuf, my favourite, rarely used gnu textutil. shuf /usr/share/dict/words|head -4|tr '\n' ' ';echo
- nikcub 15y agoye it isn't on OS X just the same, sort -R is GNU only and not POSIX
- gjm11 15y agoDANGER: This gives no more entropy than what srand() uses, which (at least for GNU awk) is simply the current UNIX time, which (if we assume that when you generated the password is known to within one year) means only about 25 bits of entropy.
- nikcub 15y agosrand in awk is platform specific. on most recent is isn't a straight call to srand(). I have another version that I use that stuffs srand but in the end I figured srand from a 250k dictionary is still better than picking words out of your head from a ~1k dictionary
- gjm11 15y agoI looked at the trunk code for gawk on Savannah when I wrote the above. It passes the output of time(0) straight into srand(). The size of the dictionary doesn't matter (given that it's more than about 70 words); the limiting factor is the entropy in the RNG seeding.
- Khao 15y agoI remember wanting to sign up on a website that had the worst password "feature" ever : you typed your password in a plain textfield, and once you clicked away it was changed to a password field. Seeing as how this "feature" was on the main page I decided never to use this service and sent the website an e-mail saying that their password field is not clever but instead is a big fat counter-security measure. Edit : I managed to find back what website it was : http://www.advirtus.com/ http://www.advirtus.com/ when you register it shows the password as you type it
- CWuestefeld 15y agoI think that's fantastic. 1: what purpose do the stupid asterisks serve, anyway? I understand them on an ATM machine, but not on my desktop PC or phone. 2: Very frequently (like, maybe 50% of the time) when trying to type a password on my phone, I miss the little "key" and mistype, but can't see that I did. I have to make multiple tries at entering the password. This feature would prevent that. So it looks like all upside, with no cost (when used only in appropriate contexts).
- Khao 15y agoI agree that this feature is good while working with a smartphone, but I'm pretty sure Android has a settings somewhere to always show the last letter you typed in every password field. I would be surprised if there wasn't a setting for that also on iOS. The thing is, I think it makes perfect sense to implement this in certain situations, but at an OS or browser level, not in the website or inside an application. Passwords are something we have grown used to and we always expect them to behave the same way! If we were to change the way passwords are handled, it should be consistent across everything. For example, browsers could implement password fields with a checkbox next to it that lets you show/hide password at your will. The fact that this website has only one setting (always show when in focus) is scaring me.
- roc 15y ago> "I would be surprised if there wasn't a setting for that also on iOS." That's the default behavior for password fields in iOS. Trick is, when you have a long password it takes far too long to shift focus from the keyboard to the text field to verify each character before moving on. I'd very much like to have a client-side show/hide button for password fields.
- wcoenen 15y agoNote that 44 bits of entropy is still nothing if you want protection from off-line attacks on password hashes. A couple of GPUs together can calculate a billion hashes per second, which eats through 2^44 possible passwords in only a few hours. This was recently demonstrated when the mtgox password database was compromised. edit: but this shouldn't be a problem if the password is properly hashed with bcrypt or some other scheme with a work factor.
- salvadors 15y agoBut this approach scales at a much faster rate. Simply adding a fifth word throws even a billion-per-second attack out into hundreds-of-years territory.
- billybob 15y agoExample generated phrase: "married greatly snake battle" These phrases would be easier to remember if they made grammatical sense. Like Chomsky's famous "colorless green ideas sleep furiously" - the words relate to each other grammatically, even though it makes no sense. Imagine memorizing "married greatly snake battle" vs "married snakes battle greatly." I think the latter is easier.
- burgerbrain 15y agoEntropy would take a serious hit if you did that.
- kragen 15y agoNot necessarily. If only one-fourth of all English words are grammatical after an average prefix, then you lose two bits of entropy off each word after the first. I suspect that the actual situation is not as bad as that. You might end up using "uncommon" words like "deceased", "advent", "fearful", and "ram" to compensate, instead of more common words like "strongly", "contains", "afterwards", and "corporate", but that doesn't seem like a major loss to me.
- gjm11 15y agoFor what it's worth, Google finds more hits for "fearful" than for "afterwards" and more for "ram" than for "corporate". ("Strongly" and "contains" do beat "deceased" and "advent", though. And yes, many of the hits for "ram" are really for "RAM".)
- kragen 15y agoMy frequencies are from this word frequency list from the British National Corpus: http://canonical.org/~kragen/sw/wordlist http://canonical.org/~kragen/sw/wordlist
- burgerbrain 15y agoAny narrowing of the search space will most definetely reduce entropy.. by how much is calculatable but I don't have the time nor language statistics right now to do it.
- tgrass 15y agoThis still creates a false sense of security since it seems (and I stress seems) to implicitly suggest you can use the same password on every site (I assume this since the argument for its use is the ease of remembering). If one site you visit handles passwords in plain text and it has your email, upon a breach all your accounts are effectively compromised.
- julianpid 15y agoI find the idea incredibly stupid. If I know someone who used that precise generator to produce his password. Then I know that the generator has less than 2000 words in the dictionnary. It then takes me only a few minutes to guess his password, rather than 550 years. Conclusion: Don't ever use this password generator, write you own, and tell no-one about it.
- zokier 15y ago4b02d9f6353a8f36fbb092f040d5a31cdf6841f2 You up for a challenge? I just generated a pass phrase with this generator, and hashed it with SHA-1 (echo -n ... | sha1sum), no salting or anything else special. Feel free to brute force it.
- julianpid 15y agoI wrote this piece of code: https://gist.github.com/1149417 https://gist.github.com/1149417 It's currently running at 3200000 tries per second on my Xeon machine. I am probably going to get bored before I find the right combination because I calculated it could take up to 52 days. :) But anyways, it is still a lot less time than trying to bruteforce something like Tr0ub4dor&3 in my opinion. It seems you like challenges, if I gave you a SHA1 hash of something similar to "Tr0ub4dor&3", would you be able to crack it (without rainbow table) under 52 days ? I don't think so.
- salvadors 15y agoLet's say the dictionary only has 1000 words in it. A phrase of four words in a row from that is still 1,000,000,000,000 possibilities, which is going to take you significantly more than a few minutes to work through at 1000 tries per second.
- pguzmang 15y agoThis article is math true, however, hackers no longer use brute force attacks and the most popular method is to attack a weak website like for example a not very popular blog, then if they succesfully broke it they have a password and a email account from you and if they are very lucky you have the same password for the email account, so, they got you. Therefore, nowadays it is safer to have different passwords for every site. Personally, I love to use lastpasss for my personal use and keepass for the office to store and manage passwords. Obviously, the weakest link of the chain is my password for the password manager application. Any of you use a different password manager?
- Adaptive 15y agoYou can add a variety of two factor authentication options to lastpass (phys OTP, yubikey). You can also allow/disallow "offline" access to your lastpass account when using these two factor options (force second factor at all times or allow single factor if offline).
- redxaxder 15y agoWhen picking a password, you don't just care about the entropy. You also care how far down the password guessing order it is. People who want to guess a password don't just brute force at random. They use a guessing order that goes through more common classes of password first. So if correct horse battery staple becomes a popular password scheme, these will end up attacked before other password schemes. (See http://www.schneier.com/essay-148.html http://www.schneier.com/essay-148.html) Unless you're going to use a password safe full of nasty passwords, you should pick your passwords using an unpopular method.
- salvadors 15y agoThe point is that this approach pushes brute-force guesses out into territory that makes it unlikely anyone will crack it even if they know exactly what scheme you're using. People seem to be massively underestimating just how long it would take to brute-force four dictionary words in a row.
- GFischer 15y agoThe link posted on the article merits a submission by itself: "The science of password selection" (a breakdown of common passwords by selection practices, as taken from public leaks) http://www.troyhunt.com/2011/07/science-of-password-selection.html http://www.troyhunt.com/2011/07/science-of-password-selectio... In short, passwords are chosen from: People names: this includes a list of about 26,000 common first and last names. Place names: this is everything from towns to states to countries and includes about 32,000 entries. English dictionary The most common passwords by group: Name: 1. maggie 2. michael 3. jennifer Place: 1. dallas 2. canada 3. boston Dictionary Words: 1. password (oh dear) 2. monkey 3. dragon Numbers: 1. 123456 2. 12345678 3. 123456789
- kragen 15y agoIs it possible that the breached Sony passwords he was analyzing may have been cracked with dictionary attacks? Maybe the reason only 1% of the passwords had a non-alphanumeric character was that the crackers mostly didn't crack the passwords that had any non-alphanumeric characters.
- numeromancer 15y agoWhat a great article! I'm changing all my passwords to "correct horse battery staple" today!
- kingsley_20 15y agoIf you're bi-lingual in a non-european language, transliterating obscure phrases from the other language could work well. For example, the poetic title திரிகூடராசப்பகவிராயர் would transliterate to thirikUdarAsappaKavirAyar. Add some subs & punctuations and I'm done - very rememberable (at least for me) :).
- pedro_a 15y agoAssuming there are 1024 languages in the world you added 10 bits of entropy. That can be achieved adding an extra common word.
- absentbird 15y agoThis is how I come up with passwords; I find a phrase that I can remember without too much trouble then I use the first letter of each word to make a password. Phrase: Three Rings for the Elven-kings under the sky, Seven for the Dwarf-lords in their halls of stone Password: 3RftE-kuts,7ftD-lithos Easy to remember and highly secure. I have been using this method for years. Bonus example: Four score and seven years ago our fathers brought forth on this continent, a new nation, conceived in Liberty 4sasyaofbfotc,ann,ciL Less secure then the last example but still strong. Especially if you use uncommon strings like the words to a song by a local band or a phrase from the newspaper or an unpopular book. That way even an attack targeting this method will take a long long time.
- kragen 15y agoThis is probably not as secure as the xkcd scheme if you don't make up the phrase yourself. See my comment above with calculations about a variant of this scheme. I suspect that both of your example phrases are among the million most quoted phrases in the English language, giving them entropy of under 20 bits.
- rubberbandage 15y agoThis is the same method Apple officially recommended in their help for choosing a secure password—the example they gave was “Tnf,tfws95” (“That’s not flying, that’s falling with style”) followed by the year of Toy Story’s release (where the quote is from). I agree that it’s an excellent combo of passphrase and obfuscation. Unfortunately, their documentation now[1] gives the same kind of example that XKCD points out will be exceedingly difficult to remember correctly. [1] http://support.apple.com/kb/HT1506 http://support.apple.com/kb/HT1506
- vidyesh 15y agoGreat so now we soon would find a xkcd-brute-force-attempt-list.txt
- juanefren 15y agoI have just created a spanish version, that is easier to fork to other languajes. http://dl.dropbox.com/u/1990697/pw_gen.html http://dl.dropbox.com/u/1990697/pw_gen.html
- dkokelley 15y agoI still sense a problem. While these passwords ARE easier to remember, there is still the security flaw that most people reuse passwords. A key-logger or shoulder-surfer could snag this (or a website could store your password in plaintext and be compromised) and then it's game over. Password managers are the future. They can memorize unique passwords of any length and complexity for every website you use, and they can store the passwords with very strong encryption with 1 key that is memorized. That key is where a password like 'correcthorsebatterstaple' could be effectively used.
- epscylonb 15y agoThis kind of misses the point. A password doesn't necessarily need to be something that is easy to remember. It just needs to be a unique token that is easy for you personally to present when needed. I currently use a keepass file stored in my dropbox folder. I am not certain what the silver bullet to online authentication will look like. However I suspect it may not require you to remember more than one secure password, perhaps not even that. Trust online is hard though, looking at the problems establishing trust online reminds me how clever human beings are, we sometimes make mistakes but we are pretty good at evaluating trustworthiness in the real world.
- codebot 15y agoFunny comic as usual, but the 20 years thing is probably invalid. How long would cracking tr0ub4dor&3 on a 486 take? Also I remember some systems didn't allow pass phrases back then. Windows NT in particular had a max password limit of 14 characters, iirc.
- kragen 15y agoFaster CPUs don't necessarily mean you get more than 1000 auth requests per second against the web site you're trying to brute force.
- presto8 15y agoFour English words selected randomly from a large dictionary is certainly secure. But it's unwieldy to type 20+ character passwords. I prefer 10-digit random alpha-numeric passwords, although these are hard to remember and type. Best compromise in my opinion is to use a hashing function with a moderately difficult passphrase, e.g., Site_Password = Hash( Domain_Name || Passphrase).
- Dove 15y agoI find the discussion surrounding the XKCD strip alarming for the superstition it reveals about password generation. The particular theme I am alarmed by is that people seem to think that if a password looks alien, or was difficult for them to come up with, it will be hard for a machine to guess. Look, we're working with big numbers here. You need to do the math. In this thread alone, I've seen suggestions to use a common dictionary word translated into another language, or written in l33tsp34k with some permutations. From a probabilistic perspective, these are still dictionary words, even though they look like gibberish. The same is true of the common method of typing a word with ones fingers displaced on the keyboard. Conversely, I see a lot of argument that these XKCD passphrases would be easy to guess because they are made up of dictionary words. This misunderstands the math behind the situation. Even if an attacker knows that your password was generated via this method, and even if they know the word list you used, the password is still hard to guess. The difficulty grows exponentially with each word in the phrase, and that's pretty fast. The key with passwords is not to create something that looks random -- something that if you showed it to another human being, they'd have a hard time deciphering. It's to create something that is random; literally a result of a throw of the dice for every new password. Human beings are really bad at creating randomness. There's a demonstration done in an early statistics class in which the professor divides the class into two groups. He tells one to toss a coin a hundred times and record the sequence of heads and tails, while the others are to write down a sequence they think is random using their imagination. The papers are completed and mixed and then -- magically! -- he is able to sort them into the two types, easily and with high accuracy. The lesson is this: even when you think you're being random, you probably aren't. You're probably using the same tricks everyone else is, and making the same mistakes. I would trust passwords that come out of a script like this to be far more secure than passwords anyone (myself included) made up, no matter how random they're trying to be.
- Cushman 15y agoThis should be higher up. It's scary to see people — intelligent people, I'm sure — saying things like "And that goes even higher when you add punctuation!" No, it doesn't. All of the reasonable punctuation you could add to a sentence adds only a few bits of entropy at best. It also makes the sentence harder to remember— was there a comma or not? Adding unreasonable punctuation or symbols is even worse— you get slightly more entropy at the cost of a password that is way harder to remember. The crucial point here is that four random words, separated by spaces, selected at random only from the 2000 most common English words — EVEN IF your attacker knows that your password is four random English words from the 2000 most common separated by spaces — already is a very long random string. If it's not random, each common English word you add adds 11 bits, and is only marginally harder for most English speakers to remember. Conversely, choosing "random" extra characters to add in makes it slightly longer, very slightly more random, and way, way harder to remember.
- Shenglong 15y agoDoes anyone else here not really remember their main password? Mine's all in muscle memory and I can't write it out unless I imagine a keyboard.
- shinratdr 15y agoI wish that was why I didn't know my password. The real reason is that 1Password manages that part of my life for me so all my passwords are long randomly generated strings that I don't know.
- shin_lao 15y agoDon't forget to add "correcthorsebatterystaple" to your dictionaries kids!
- abecedarius 15y ago"It's a novel idea." No, I posted about my own generator in 2005: http://darius.livejournal.com/38591.html http://darius.livejournal.com/38591.html (getting the words from Beowulf). Then Zooko or Kragen pointed out some even older system in response (I forget the name).
- ajross 15y agoCompuserve was generating automatic account passwords in the early 1980's from two dictionary words and a non-alpha character in between them. Mine was "sleeve;coast". No doubt they didn't invent the trick either.
- frosas 15y agoHow does one calculate password entropy? I deduced this one: entropy = log2(symbols^chars) But using 63 symbols ([a-zA-Z0-9&]) I get 65 bits for Tr0ub4d0r&3, not 28.
- wcoenen 15y agoYou are making the same error that led to the popularity of passwords based on a common word and some substitutions. Your calculation is for 11 characters, each chosen completely at random out of 63 symbols. People don't chose a password that way - we typically can't generate or remember random symbols. XKCD's calculation is for a common word + common symbol substitutions and additions: log2(#words) + log2(#capitalization options) + log2(#substitution options) + ...
- kragen 15y agoYou calculate password entropy of a password drawn from a set of equally likely passwords by taking the log_2 of the size of the set. (This is a convenient special case of the more general formula for entropy.) A convenient thing about this is that if you concatenate two things (in such a way that you can pull them apart again) the number of possibilities is the product of the possibilities for each of the things, so the entropy is the sum of the entropies.
- ajross 15y agoI can't help but think that this is a solution to the wrong problem. The big problem with password security in the modern world really isn't that they're easy to break, but that they're pervasively reused between sites. So breaking them (for example, by reading them in plain text out of a dumb database!) in one place opens up attacks on higher value accounts. The fix, of course, is to get users to stop re-using passwords between sites. How does making passwords more memorable fix this? If anything, forcing users to use random base64 strings strikes me as more secure as they will be forced into some sort of password locker implementation by their inability to remember them.
- crizCraig 15y agoRight, maybe if you use the first letter of the words in a sentence, like "Hey Jude, don't make it bad, take a sad song, and make it better." -> "HJ,dmib,tass,amib." Then you can add in some characters that make it different for each site without it being obvious which characters you added. I wrote a blog post on how to create different passwords for sites that are easy to remember: http://craigquiter.com/post/8668237043/creating-and-remembering-good-passwords-plus-some http://craigquiter.com/post/8668237043/creating-and-remember...
- aidenn0 15y agoWatch out for sites that only use the first 8 characters of your password (no matter how long it is).
- abalone 15y agoThis scheme could be easily guessed by a dictionary attack that simply ran through combinations of dictionary words instead of individual characters. If this became a popular scheme, the whole entropy argument goes out the door. It only has more entropy if we compare the two schemes on a character-by-character basis (~10 vs. ~25). Of course the longer string will appear to have more entropy. But if a password guesser expects the pattern of the "four common words" scheme, as they might if it became popular, it's not nearly as entropic. A better comparison would be to consider each word as a single "character" from a 180,000 sized alphabet (for an English dictionary). Calculate the entropy of that and you'll find it's in the same ballpark.
- kragen 15y agoIf you took the suggestion in your last sentence instead of offering it to the rest of us, you would see that the entire rest of your comment is incorrect.
- marze 15y agoIsn't this discussion premised on a server configured to allow fast password guessing indefinitely? This is 2011, shouldn't every server be configured to allow a guess every two seconds for 20 guesses, then every 10 minutes, or something similar? I'm not familiar with common practices in this area, but why wouldn't all such services be configured to limit the incorrect guesses?
- ry0ohki 15y agoMost really strong systems lock an account after a couple of incorrect guesses. I assume this is all for systems that may not be secured to prevent brute force.
- mtogo 15y agoLocking the account is the wrong way to go about it since it makes DoS on known accounts trivial. Blocking the IP or an increasing time between tries is, afaik, the "right way".
- alanh 15y agoCareful! This is only using `Math.random` and does not attempt to use `window.crypto.random` (though most browsers do not support it yet: http://jsfiddle.net/alanhogan/trUYu/ http://jsfiddle.net/alanhogan/trUYu/) or anything that would attempt to bring real entropy into the process. I don’t mean to fault the creator of this page, but at the same time, I would not trust this generator for important passwords, simply because you cannot know if others are getting the same 'random' results as you are. More info on SO: http://stackoverflow.com/questions/5651789/is-math-random-cryptographically-secure http://stackoverflow.com/questions/5651789/is-math-random-cr... PDF on the topic: http://www.trusteer.com/sites/default/files/Temporary_User_Tracking_in_Major_Browsers.pdf http://www.trusteer.com/sites/default/files/Temporary_User_T... > In the Javascript engines of IE (Trident), Firefox (Gecko), Safari (WebKit) and Chrome (V8), the output of Math.random() can be used to reconstruct the random seed, and thus provide both this seed and the current “JS mileage” (i.e. the number of times Math.random() was invoked).
- kragen 15y agoI wouldn't use a JS program served from somebody else's website to generate my password anyway. How do I know it's not sending them a copy of the passwords it generates?
- alanh 15y agoWell, I watched network connections and saw none. Do that + use Incognito mode = you're probably good.
- kragen 15y agoHe recently changed it to use a random seed sent from the server instead of the client-side RNG. Over, I believe, unencrypted HTTP. Your suggested countermeasure would not have detected that attack; indeed, perhaps it was already in place before you reported no evidence of attacks. It would, however, have made it harder for him (or your ISP) to tell whose password they'd stolen.
- ssapkota 15y agoI blogged on the same issue almost 2 months back: http://goo.gl/4Sxf6 http://goo.gl/4Sxf6
- Aloisius 15y agoPersonally I think password entry should be done in madlib form. Each user would have a unique madlib prompt like: Username: ___________ Password: Twelve ___(pl. noun)___ jumped over a ___(adjective)___ ___(noun)___ named ___(proper noun)___.
- ErikRogneby 15y agoAmazon has implemented this. It's called payPhrase: https://www.amazon.com/gp/payphrase/claim/select-phrase.html https://www.amazon.com/gp/payphrase/claim/select-phrase.html
- ryanelkins 15y agoI just hate sites that won't accept spaces and restrict how long a password can be (usually to something relatively short like 8 or 12 characters). Also, many require you to use mixed case and/or numbers or "special" characters. I usually just use complete sentences.
- harshpotatoes 15y agoIt's a good idea, and would work well, if only websites would let me choose passwords longer than 12 characters!
- pedro_a 15y agoRandall is saying exactly that: Through 20 years of effort, we've successfully trained everyone to use passwords that are hard for humans to remember, but easy for computers to guess
- tucosan 15y agoas embarrassing as it may seem, although having read the good part of this thread, i still don't understand why a four word password, can be more random than something i would get like this: ~$ pwgen -s 8 C0olz5KM Would anybody care to explain this to me, or at least point me to a good place where i can read up on this?
- kragen 15y agoAssuming pwgen isn't actually defective (I haven't looked), you can get more entropy in a shorter password with pwgen. The above looks like 6 bits per character to me, so 48 bits in all. That's 4 bits greater --- 16 times better --- than Randall's estimate for "correct horse battery staple", which is much longer. But "correct horse battery staple office" gets you up to 55 bits. Is it going to be easier to remember "correct horse battery staple office" or "C0olz5KM"? And how about typing them without making errors?
- xkcdentropy 15y agoThe XKCD comic is only partially correct. Depending on what source you believe English text has about 0.6 to 2.3 bits of entropy per character. This means you need somewhere between 4.7 and 18.3 characters in each word to reach 11 bits of entropy per word. Assuming entropy is closer to 2 bits per character this is a realistic situation. However, when you assume entropy is closer to 1 bit per character the words have to be too long to be realistic.
- redslazer 15y agoI tried to generate all possible permutations of 4 of the 2000 most popular words in the English language. My computer failed miserable after about 2000000 permutations and considering there is 10^13, i wont be making a rainbow table for this new type of password.
- mathattack 15y agoThe beauty of this discussion is not just "How to create memorable but hard to break password?" but "How much deep insight can a 4-6 frame cartoon contain?" The signal to noise ratio of xkcd is fantastic! They've again zipped a great discussion in just a few frames.