3 ms·
>From a human-memorable standpoint, that's no better than using an actually randomly generated passphrase. Are you seriously arguing that "The quick brown fox
by commandar 14y ago
>From a human-memorable standpoint, that's no better than using an actually randomly generated passphrase.
Are you seriously arguing that "The quick brown fox Jumps over the lazy dog!" is less human-memorable than "dlLejs$sAgkCnzklS%9sxckAAnvk"?
Any variation from what a precomputed table expects renders the table useless.
>It's no better from a computer-guessable standpoint, either.
Besides the increased key space that has to be attacked?
- lotharbot 14y ago> "Are you seriously arguing that "The quick brown fox Jumps over the lazy dog!" is less human-memorable than "dlLejs$sAgkCnzklS%9sxckAAnvk"?" I didn't say "password", I said "passphrase". Something like "breath red long provide" or "itself even willing establish". If you're using memorable movie quotes or Shakespeare quotes or anything else that you could find on wikiquote, your keyspace is going to be smaller than what you get from stringing 4 random words together. You can try to grow that keyspace by adding in variations, each of which will get you a few bits of entropy, but those variations come at the cost of memorability. It's counterproductive to start with a non-random phrase like a quote, and then try to add randomness on top of it. If you want both entropy and memorability, use a randomly generated passphrase (via http://passphra.se http://passphra.se or by using dice and a dictionary) instead of piecemeal randomness-on-top-of-non-random-quotes strategies.
- commandar 14y ago>It's counterproductive to start with a non-random phrase like a quote, and then try to add randomness on top of it. The primary attack vector against WPA2 keys is via precomputed tables. If your concern is about your SSID+passphrase combination appearing in one of these tables, any variation whatsoever from the "canonical" version somebody might pull from, say, a database of quotes is negated and they're forced back to square one of a pure brute force attack which the increased key space makes more expensive.
- lotharbot 14y agoThe point I'm trying to make here is that you can negate that attack vector by just using an xkcd-style passphrase, which always works, and which is typically more memorable than a mangled quote. The xkcd-style passphrase is simply better than ad-hoc solutions.
- commandar 14y agoThe thing is, your entire line of argument is predicated on the quote approach being vulnerable to a dictionary-style attack. In order for that to be the case, both the SSID and the exact quotation used have to match, otherwise the attacker is forced back into expensive brute force attacks. Any unique element, whether intentional or not, renders that vulnerability null. The xkcd approach certainly works, but the arbitrary, random nature of it is going to make it difficult for some people to remember. The quotation approach is just leveraging the fact that people spend their entire lives using language as a logical framework to simplify remembering things. Either is going to be vastly more secure than a random string of characters.
- lotharbot 14y agoMy line of argument is more complex than you give it credit for. It has 3 major components: - if you do not include "unique elements" (that is, you quote straight from wikiquote or similar), a quote is less secure than 4 random dictionary words due to being subject to wikiquote-driven dictionary-style attacks. - if you include intentional and unique modifications, a quote from a public work like a movie or play is not particularly easier to remember than something from passphra.se or similar. Once you have to remember what you spelled/capitalized/punctuated in a nonstandard way, what have you really gained? - if you include unintentionally unique elements (a word you always misspell), or elements that aren't really unique (you always append the same character), then your passphrase is vulnerable to a dictionary-like attack by an attacker who has some knowledge of you, particularly one who you've told your scheme to. The key to the xkcd-style passphrase is that it remains secure even against an attacker who knows how you generated it, and who knows your personal tendencies. It's a completely universal, memorable, secure scheme. Movie quotes are secure and memorable enough the majority of the time -- vastly more secure than using your kid's name, vastly more memorable than a string of random characters. But it seems to me like you're advocating a second-best security practice when we already have a best one.
- eric_bullington 14y agoOr if you're on Linux: shuf -n4 /usr/share/dict/words | tr -d '\n'; echo
- phaemon 14y agoActually, just: echo $(shuf -n4 /usr/share/dict/words) will do the trick. Though it does have some weird words in there. A trimmed "4000 common words" dictionary is what I use.