8 ms·
Some evidence on multi-word passphrases
- gizzlon 15y agoInteresting read.. Assuming people would choose random words in their passphrases always seemed too simplistic and naive.
- user24 15y agoIt doesn't even have to be random, simply choosing "SimplyChoosing" or "AssumingPeople" is way more secure than "ManchesterUnited" or "HarryPotter", but still people are creatures of habit.
- lhnz 15y agoEverybody is dancing around reality: passwords are incompatible with the average person. The best passwords are almost always difficult to memorize and once they are memorized it is costly for us to change them. It's an ill-fitting solution to a social problem.
- nknight 15y agoA random 4-word passphrase is more than enough to stop online attacks against high-value targets (e.g. bank accounts) that have any throttling at all. A random 5-word passphrase with three random characters tossed at the end has better than 82 bits of entropy and will halt offline attacks, at least by non-TLAs, for many years to come. These are not hard to memorize. What's hard to memorize is 101 different passphrases, many of which you don't use every day, which is why the people actively working to make it easier are focusing on the management problem.
- drostie 15y agoJust to give people a flavor, here is a script I wrote in Python to generate various random passwords: http://www.bpaste.net/show/24775/ http://www.bpaste.net/show/24775/ What it looks like in practice: drostie@signy:~$ words -c 5 4 (Line entropy: 64.7055497954 bits.) rebelliousness subpoenas garrulous coach mono peroxide underused fathers entreat entwined meatier umbilicuses relay torrential husband Jenkins Kristine sluggers feverishly Lessie So each of those lines has a little over 64 bits of entropy. You might also consider the following one-liner in the shell: drostie@signy:~$ head -c 9 /dev/urandom | base64 ST2QpSb0eKHk If you're not paranoid, consider typing "password" into DuckDuckGo and it will give you a random password. If you're slightly more paranoid, consider using mouse-movements to generate your own random password with a random tool I coded for making random API keys: http://code.drostie.org/api.html http://code.drostie.org/api.html . Just truncate to the first 10-12 characters or so.
- danieldk 15y agoThat's why password managers are so useful. For every service a user can use a different strong password, but for the user there is only one password. Of course, password managers have their weaknesses (a compromised system will often give access to all accounts, rather than just a few), but it is far more secure than having people using the same trivial password for every service.
- pnathan 15y ago
- napoleoncomplex 15y agoAs with normal passwords, you will have people completely disregarding any advice on how a password should look like. People will just slowly learn that having a faulty security system on the web is the same as it is in real life. You don't put a curtain as your front door, and you shouldn't put "Harry Potter" as your passphrase, especially if you are holding a wand in your Facebook photo. In my case, I use multi-word passphrases with words from a obscure dialect of a tiny European country's language. Being a dialect I grew up with, it has the benefit of being easy to remember, and the obscureness of it means the phrases itself are more or less a random string of characters to any brute-force attack. Not exactly a "best practice" for anyone but myself, but I'm happy with it :).
- ttt_ 15y agoThe real problem of passwords in general is the complete lack of a standard to what a password can be. Basically every service with a login reinvents the whole damn thing with completely arbitrary rules that are incompatible with each other. Minimun and maximun length, case-sensitivity, digits, letters, special characters, spaces. Ok, after reading a lot about passwords I decide that I'm gonna go with a condensed passphrase more than 10 characters long and with a couple service-contextual caharcters in the end. That oughta keep me safe right? Well, except I have to pick a 6-8 length password that MUST have a number AND a capitalized letter in it!
- wisty 15y agoSilent truncation is another gotcha. They drop everything after character 8 (so it fits in the database?). Then they change the schema, and stop truncating at 8 characters, but only on some forms. Oh, the joy.
- ovi256 15y agoMSN and Hotmail used, and maybe still do this, after 14 characters.
- cpeterso 15y agoI think the common problem of silent truncation after 8 characters suggests they are using the (outdated) crypt(3) API. The man page says "By taking the lowest 7 bits of each of the first eight characters of the key, a 56-bit key is obtained."
- drostie 15y ago
- 16s 15y agodiceware is very good for these sort of passwords. I have no affiliation, but would use it for passphrases if I needed to. http://world.std.com/~reinhold/diceware.html http://world.std.com/~reinhold/diceware.html
- TheCapn 15y agoThis doesn't actually surprise me. If you consider the role of random brute forcing via dictionary attacks is to locate the appropriate order of tokens that work together to create a coherent meaning you're essentially not providing any more security with more words. A "Password" is a phrase composed of tokens that are the alphabet, numbers, symbols. A "Passphrase" is composed of tokens that are known english words. By taking the corpus search method to determine natural phrases they're essentially trying to identify the total breadth of 2+ token combinations that make up the english language. This does break down like they said when you stop using coherent meanings. A passphrase that is HorseQuoteBulb would be hard to guess in comparison to HorsesEatHay or something of the same style. The same goes for passwords: while it may be easy to guess a password as "phrase" it suddenly becomes a lot more difficult to randomly attempt guesses at "7_-Az!e". Eventually I think we'll all be forced to use two factor authentication for added security. Here the user is mostly safe from their own ignorance where the danger of having credentials stolen is more prominent in the form of Man in the Middle attacks.