8 ms·
> A secure-but-readable password generator I love pronounceable passwords, but there's research indicating that such generators typically produce lower than ex
by edpenz 4y ago
> A secure-but-readable password generator
I love pronounceable passwords, but there's research indicating that such generators typically produce lower than expected entropy. Do you mind sharing what algorithm you use?
- omaranto 4y agoI think the generator from xkcd sounds pretty good. https://xkcd.com/936/ https://xkcd.com/936/
- heyoni 4y agoProblem is so many websites have these arbitrarily low password lengths that usually max out at 20 characters.
- bombcar 4y agoWorse are the ones that let any length input but only read the first ten characters or so.
- lucb1e 4y agoI haven't seen those in a while now. For random sites you should use a password manager anyway though, not try to remember a thousand passphrases. You're going to end up reusing passwords if you try to memorize them all, or else you'll have to write some down and then you are already using a password manager :). Or you use a system and then 1-2 cracked passwords/-phrases will likely break them all. Note that this advice is for the average, common site. If you have special considerations for your bank, broker, or similarly high-value sites, different advice might apply of course (but this is not really the place for that and there are already enough recommendations online).
- Jaruzel 4y agoFor ages I remembered this as 'battery-horse-staple-correct' but then I see loads of people saying 'correct-battery-horse-staple' so now I think I'm the one who is wrong. I wonder which way round is actually the right way to say it?
- mkl 4y agoNeither? As the linked comic says, it's "correct horse battery staple".
- Jaruzel 4y agook typo on my part... anyhoo - does "correct" go at the front or back?! Because the way I read it, the speech bubble saying 'correct' is after the horse and the other two words.
- mkl 4y ago"Correct" goes at the front; see panel 4. You remember the order along with the words, and the imagery is a cue to aid memory, not a script.
- Jaruzel 4y agoMaybe it's because I'm a visual learner that I stored panel 6 and not panel 4.... Even though I clearly stored it incorrectly regardless.
- deleted 4y ago[deleted]
- wiredfool 4y agoI gave up on readable. with open('/dev/urandom', 'rb') as f: return base64.urlsafe_b64encode(f.read(12))
- lobocinza 4y agoalias genpwd="tr -dc 'a-zA-Z0-9!@#$%*()[]{}' < /dev/urandom | fold -w 16 | head -n 1 | xclip -sel clip"
- lucb1e 4y agoI always find those annoying to copy (we use a lot of shared credentials, like when the customer gives us 3 accounts with different permission levels to pentest an application with) and it also simplifies the command to not have to specify all those symbols. You can also avoid the whole `fold` thing by just telling `head` to give you a certain number of -c instead of a certain number of -n. </dev/urandom tr -dc a-zA-Z0-9 | head -c 16 (Then again, you were proposing an alias, so then command complexity/memorability doesn't really matter.) Security level: log((26+26+10)¹⁶)/log(2) ~ 2⁹⁵ (95 bits of entropy), comparable with adding those 12 extra symbols: log((26+26+10+12)¹⁶)/log(2) ~ 2⁹⁹. (Adding a character makes more sense than adding a symbol if you want more security, all else being equal of course.) If a stupid application still has outdated password requirements (thankfully this is rare among the applications I use) then one can of course add the classic ! at the end.
- stirfish 4y agoSomething like cat /usr/share/dict | shuf -n 4 | tr '\n' '-' (inb4 unnecessary use of `cat`)
- heyoni 4y agohttps://porkmail.org/era/unix/award https://porkmail.org/era/unix/award (Sorry I had to)
- lucb1e 4y agoI posted some advice in a sibling thread, <https://news.ycombinator.com/item?id=31021503 https://news.ycombinator.com/item?id=31021503>, that applies here as well: > Please don't use $RANDOM or $((RANDOM)) or standard `shuf` for password generation. These RNGs are not cryptographically secure. Use input from /dev/urandom instead.
- LeoPanthera 4y agoYou can do this with "shuf --random-source=/dev/urandom". The same with gshuf. I use an alias to add this switch by default.
- lucb1e 4y agoWhen using shuf for cryptographic purposes, I'd first check if it advertises as being able to be a secure cryptographic token generator when provided with a secure random source. It might very well use modulo operations, for example.
- jmholla 4y agoI use cat like this all the time. It means I can easily change whatever program I'm using to interact with the program (e.g. switching `tr` to `sed`).
- yakubin 4y agoYou can replace "cat /usr/share/dict |" in that invokation with "</usr/share/dict" and it will be equally easy to switch between tr and sed. Yes, you can put that redirection at the start, not just at the end of a command line. Although I admit I still haven't got used to doing it.
- slowbdotro 4y agoNot OP, but I prefer memorable passwords, thus, correct-battery-horse-staple style passwords in bash: (Install cracklib, or any dict file) #!/bin/bash pickaword() { WORDFREQFILE=/usr/share/dict/cracklib-small; WORDLENGTH=$1; awk -v wordlength="$WORDLENGTH" 'length($1) == wordlength {print $1}' "$WORDFREQFILE"|shuf|head -n 1; } [[ ! -z $1 ]] && numWords=$1 || numWords=4 separator="-" count=0 currentWord="" while [[ $count -lt $numWords ]]; do [[ $count != 0 ]] && echo -n $separator num=$((3 + RANDOM % 10)) word=$(pickaword $num) echo -n "$word" count=$(($count + 1)); done echo "" Edit: code formatting is hard. Source is: https://gitea.slowb.ro/ticoombs/dotfiles/src/branch/main/bin/gen https://gitea.slowb.ro/ticoombs/dotfiles/src/branch/main/bin...
- lucb1e 4y agoPlease don't use $RANDOM or $((RANDOM)) or standard `shuf` for password generation. These RNGs are not cryptographically secure. Use input from /dev/urandom instead. Modulo operations like these are another thing to avoid. To get equal chances for each word, the simplest thing to do is e.g. do wordlistlength = 10e3 randomnumber = os.urandom(1) * 256 + os.urandom(1) while randomnumber > wordlistlength return wordlist[randomnumber] (Adjust if your list length is greater than 255×256+256, of course.) Further, I see that cracklib-small is 52k words. That's not good or bad, but it makes the default 4-word phrase 52e3⁴ ~ 63 bits of entropy, which isn't terrible but in my opinion on the short side as a default. It will be perfectly fine if you only ever want to defend against online attacks, but in some cases (think disk encryption or password manager) offline cracking should be kept in mind and for the rest you should usually use a password manager anyhow (so then memorability doesn't matter). Or perhaps more succinctly: please don't roll your own crypto. I understand that this is of course very unlikely to be abused if it's just for yourself and nobody knows of this weakness in your credentials (security through obscurity works... until it doesn't), but one day someone will use this as inspiration or it will spread somehow, say through an HN comment... just use good password generators or at least keep insecure ones secret. Btw: many standard Debian(-based) installations have /usr/share/dict/words available so you don't need an extra install; I haven't seen cracklib used before but that might just be me.
- lobocinza 4y agoSometimes I use passages from books. Easy to remember a >60 char password, can always check the book and it brings back to memory a book that I enjoyed each time I use it. For PINs I like to use a long sequence of digits of a physical/mathematical constant.
- rozab 4y agoFrom books? Having anything that's natural language will kill your entropy, way way below correct horse battery staple. Moreso if it's indexed by Google Ngrams.
- earthboundkid 4y agoYes. But it’s much more dramatic in the movie when the villain runs his finger along the spines of the books in your library idly but then his eyes narrow and he aggressively pulls a book off the shelf and flips it open to a well worn spot. Checkmate!
- lobocinza 4y agoTheoretically, maybe. But I'm tempted to believe that for all practical purposes it's a 60+ chars password.
- kragen 4y agoDon't. It isn't.
- tastyfreeze 4y agoJust FYI, if there is an incentive to get your password, there are existing programs to match arbitrary length strings from books or any text source. One such program has been used to steal cryptocurrency from wallets that are generated from a passphrase like NXT.
- mikevm 4y agoThat's why I also add punctuation to the phrases :), or some suffix.
- LeoPanthera 4y ago> Do you mind sharing what algorithm you use? Actually, I do mind. And so should you! I developed it myself, however, and feel reasonably confident about it.
- kragen 4y agoI'm confident that http://canonical.org/~kragen/sw/netbook-misc-devel/bitwords.py http://canonical.org/~kragen/sw/netbook-misc-devel/bitwords.... produces passwords with precisely the expected entropy, and it's secure under Kerckhoffs's principle, so I don't mind sharing it. For the ones that consist of words, the wordlist I use is http://canonical.org/~kragen/sw/netbook-misc-devel/wordlist http://canonical.org/~kragen/sw/netbook-misc-devel/wordlist, the frequencies of the words that occur 5 times or more in the British National Corpus. This representation is my favorite: The 84-bit number 10231239242746186561668573 can be represented as: ... In 12-bit words of 5 letters or less: hits towel bloke gala blah jimmy barry Diceware is good too. A word of warning: be careful playing around with stochastic text generation if you're susceptible to delusions and hallucinations. You'd have to be pretty far gone to think "hits towel bloke gala blah jimmy barry" was a message from God, but of course we all know people who have fallen into that kind of belief, and the strain on credulity gets smaller as the text model gets more sophisticated.
- brosciencecode 4y agoWouldn't a generator like this significantly increase risk of succumbing to dictionary attacks? I probably just don't understand part of what it's doing, but I'm curious.
- kragen 4y agoIt depends on what your baseline is. With knowledge of the generation algorithm, a dictionary attack on a password generated that way will definitely succeed, but on average it will take 2⁸³ tries (twice that at worst). At a billion tries per second this is 300 million years, almost long enough for the Sun to engulf the Earth if your attacker devotes only a single CPU to the task. There are commonly used password hashing algorithms that can only do a few hundred tries per second per CPU, which pushes the average success time to a quadrillion years, fifty thousand times the current age of the universe. By contrast, trying every phrase of 20 words or less in every book that has ever been published would only take something like 129 million × 19 × 500,000 = 1.225 quadrillion tries. At a billion tries a second, that's only two weeks. (And if the password hash is inadequately salted, the attacker can use a rainbow table and put in that effort ahead of time and distribute it across all the victims.) An attacker with more resources might devote a million CPUs to the problem, which would cut the time to success from 300 million years down to only 300 years (assuming a billion tries a second). In the next few decades it will become practical to devote much larger amounts of computation to problems like this, so such an attack might succeed, but currently it is beyond the capabilities of all but a few adversaries. And, as I understand it, Grover's algorithm will enable a large enough quantum computer to solve your password in only 2⁴² tries, which is only about four trillion tries, under an hour at the billion-tries-per-second speed I suggested above. I'm not sure, but I think it would need to prevent qubit decoherence for that period of time. You can get equivalent security with a shorter password that looks like random gibberish, such as b7fc d750 9a52 ad6a e48c a, eedgckeimbjdefhcjclmghh, mgujdlrgdfmadtlidu, 1qvrx21zego0scvyi, 17uUPBKnfX7fSNY, >4h)&crV,+E{O, or 宜潨阰揫難侌, but those are a lot harder to memorize. They're shorter to type, though, and they're less vulnerable to side-channel attacks. Looking random isn't good enough, though. They need to actually be random.
- throwaway81523 4y agoLook at diceware.com for a good way to do that. You can calculate the entropy without "research". I use a simple python script for the purpose, filtering out the words < 7 chars long from /usr/share/dict/words instead of bothering with the official diceware list. Example output: "snored-Hoff-virtue-tab-eroded-Perl's" with estimated 87 bits of entropy. If you write the phrase on a piece of paper and refer to the paper when typing the phrase into a computer, then after a few uses you will remember the phrase without any special memorization effort. At that point you can shred or burn the paper, or possibly record it in an offline encrypted file requiring its own security efforts.
- magicconch 4y agoAlso take a look at the EFF’s wordlists [1] as an alternative to the Diceware list. Quoting from their blog post, here are some issues with the Diceware list that they have resolved: - It contains many rare words such as buret, novo, vacuo - It contains unusual proper names such as della, ervin, eaton, moran - It contains a few strange letter sequences such as aaaa, ll, nbis - It contains some words with punctuation such as ain't, don't, he'll - It contains individual letters and non-word bigrams like tl, wq, zf - It contains numbers and variants such as 46, 99 and 99th - It contains many vulgar words - Diceware passwords need spaces to be correctly decoded, e.g. in and put are in the list as well as input [1] https://www.eff.org/deeplinks/2016/07/new-wordlists-random-p https://www.eff.org/deeplinks/2016/07/new-wordlists-random-p...
- versteegen 4y agoThanks for the link, but it's broken, should be: https://www.eff.org/deeplinks/2016/07/new-wordlists-random-passphrases https://www.eff.org/deeplinks/2016/07/new-wordlists-random-p... I think you copy-pasted it from elsewhere on HN, causing the end to be cut off.
- cm2187 4y agoAlso passwords you can select by double click (ie certain special characters) and don’t have characters that look ambiguous (ilI, oO0, etc)