5 ms·
WPA2 keys hash the passphrase and the SSID. The precomputed tables that make cracking WPA2 feasible have to not only target passwords, but password+SSID combin
by commandar 14y ago
WPA2 keys hash the passphrase and the SSID.
The precomputed tables that make cracking WPA2 feasible have to not only target passwords, but password+SSID combinations as a result.
I think you're grossly overstating the relative weakness of a longer passphrase. The more obscure, the better, obviously, but the chances of any given quote or phrase of any length appearing in a precomputed table are relatively minimal.
More importantly, any variations in punctuation, capitalization, spacing, etc would make a precomputed table worthless while still making the passphrase far easier for a human to remember than a random string of 8 characters.
- ghayes 14y ago> More importantly, any variations in punctuation, capitalization, spacing Alternatively, exact spacing, punctuation, etc. limits the human advantage of remembering phrases ("Wait, was that a capital A before the comma? Do you use two spaces between the sentences?"). This is the exact reason I've had a hard time with long pass-phrases and often generate a unique string and rely on physical protection. It's worth noting that if we stripped whitespaces (and possibly some other common "could go both ways" features), we may be able to encourage people to choose higher entropy passwords.
- commandar 14y ago>Alternatively, exact spacing, punctuation, etc. limits the human advantage of remembering phrases ("Wait, was that a capital A before the comma? Do you use two spaces between the sentences?"). Then append a random character at the end. The point is that any variation whatsoever from what's included in the precomputed table renders the table useless while being easier to remember than a purely random string of characters.
- lotharbot 14y ago> "variations in punctuation, capitalization, spacing" ... have the same problem as a random string of characters. You have to remember which letter it was you capitalized, where you put the semicolon in place of the comma, and so on. From a human-memorable standpoint, that's no better than using an actually randomly generated passphrase. It's no better from a computer-guessable standpoint, either. So instead of trying to create a new scheme for generating passwords like "mangle a movie quote", you're better off just using the xkcd method / passphra.se
- commandar 14y ago>From a human-memorable standpoint, that's no better than using an actually randomly generated passphrase. Are you seriously arguing that "The quick brown fox Jumps over the lazy dog!" is less human-memorable than "dlLejs$sAgkCnzklS%9sxckAAnvk"? Any variation from what a precomputed table expects renders the table useless. >It's no better from a computer-guessable standpoint, either. Besides the increased key space that has to be attacked?
- lotharbot 14y ago> "Are you seriously arguing that "The quick brown fox Jumps over the lazy dog!" is less human-memorable than "dlLejs$sAgkCnzklS%9sxckAAnvk"?" I didn't say "password", I said "passphrase". Something like "breath red long provide" or "itself even willing establish". If you're using memorable movie quotes or Shakespeare quotes or anything else that you could find on wikiquote, your keyspace is going to be smaller than what you get from stringing 4 random words together. You can try to grow that keyspace by adding in variations, each of which will get you a few bits of entropy, but those variations come at the cost of memorability. It's counterproductive to start with a non-random phrase like a quote, and then try to add randomness on top of it. If you want both entropy and memorability, use a randomly generated passphrase (via http://passphra.se http://passphra.se or by using dice and a dictionary) instead of piecemeal randomness-on-top-of-non-random-quotes strategies.
- commandar 14y ago>It's counterproductive to start with a non-random phrase like a quote, and then try to add randomness on top of it. The primary attack vector against WPA2 keys is via precomputed tables. If your concern is about your SSID+passphrase combination appearing in one of these tables, any variation whatsoever from the "canonical" version somebody might pull from, say, a database of quotes is negated and they're forced back to square one of a pure brute force attack which the increased key space makes more expensive.
- lotharbot 14y ago