6 ms·
Anyone using this comic to imply that a passphrase is more secure than a short random password hasn't done the math. This is comparing a passphrase drawn from
by Niten 14y ago
Anyone using this comic to imply that a passphrase is more secure than a short random password hasn't done the math. This is comparing a passphrase drawn from four of the 2048 most common words against not a random password, but one based on a mutated version of one of the 65536 most common words.
The example passphrase does have the equivalent of 44 bits of entropy:
log_2 (2048^4) = 4 * 11 = 44
However, if we take a random password formed by just seven of the 95 printable ASCII characters, we already have a password four times stronger than such a passphrase:
log_2 (95^7) ≈ 45.99
XKCD is great and all, but I wish Randall had been more clear that this comparison does not touch on the strength of a random password, because I have since seen an infuriating number of people point to it to claim that passphrases are more secure than random passwords. They are not.
- pyre 14y agoPassphrases are more secure than random passwords when you factor in the human element. A 64 character passphrase is more memorable than a 64 random character string and less likely to be written on a post-it note.
- apawloski 14y agoBe careful -- you're starting to argue a slightly different point than what your parent made. You're not wrong, but you also haven't done anything to dismiss his claim. He's talking about a 7 character password vs a 4-word passphrase. Not equal sized, 64 character passwords.
- deleted 14y ago[deleted]
- catharsis 14y agoThis assumes that it is known that the password is four random words. The security of this method hinges on the fact that that information is not known.
- miles 14y agoExactly. In a thread about "900gage!@#" being cracked in a few hours[1], this same discussion came up. It's worth reading for those who are wondering about passphrases vs. complex passwords. [1] http://news.ycombinator.com/item?id=4545893 http://news.ycombinator.com/item?id=4545893
- Niten 14y agoThis is, again, not about a random password, as moxie explains in that thread. And as he continues, with regard to the comic: "I think that's totally on the right track, but if people start to do that, chances are that they'll start to create exploitable patterns again". Any password cracker smart enough to exploit the patterns in "900gage!@#" is also smart enough to exploit the construction of an English language passphrase. The passphrase is still secure enough (probably), but it is not more secure than the random password. And if there is any one thing to take away from that thread, it should be that it's foolish to assume the obscurity of your passphrase's formulation gives you any extra security whatsoever.
- miles 14y agoThanks for your reply, Niten! Sorry, I didn't mean to imply that "900gage!@#" was random, but many people would (wrongly) consider it complex. Users who are not generating and storing random passwords (with KeePass or the like) may make safer password decisions when thinking in terms of a phrase rather than a "complex" word. Of course, they'd be far safer still by using a good password manager and long, truly random passwords.
- Niten 14y agoThat's not the case, though. Even knowing the general manner in which the passphrase is constructed, if the four words are randomly selected then the best an attacker can do is to brute force the space of 2^44 possible phrases, which is difficult enough to be considered secure. The very same can be said for the seven-character random password: the best an attacker can do, knowing how the password is constructed, is to brute-force a space of about 2^46 possible passwords, which is secure enough. And this must be true in order for passphrases to be a reasonable choice. Because if people start using passphrases commonly, then this formulation will immediately be added to password cracking toolchains along with all the other common types of password. On the other hand, the passphrases's actual "entropy" is probably lower than the advertised 44 bits, because patterns like the appearance of an adjective ("correct") before a noun ("horse") are common enough in the English language that they, too, could be factored into a smart password cracking tool.
- Terretta 14y ago> to imply that a passphrase is more secure than a short random password I noted to internalize the idea, the entropy idea versus human "random" passwords which aren't random at all. "Normals" are using their name with a 3 instead of an E, or some word with a 1 on the end. This tends to put them in rainbow tables or easy attacks. See my link #1 in GP comment for reference. That's why I said "pass-phrases are stronger than monkey rules". Meanwhile, "random" passwords don't necessarily come up stronger. Forget just seven. Let's use 1Password's random sixteen (16) char generator as an example[1]: 2Fro%7gMfQbwBktm : 85.3 bits of entropy from 72 char set [xNyCHZc44RzPeMJ : 85.1 bits of entropy from 82 char set Meanwhile, going by length and charset alone and ignoring whether the characters are words (using my passphrase from GP comment): thisphraseisdefinitelynotinthedictionary : 153.7 bits of entropy from 26 char set The thing is, when you're attacking Evernote's database, you don't know someone's using XKCD's idea. So you're not looking at (2048^4) [2]. You're looking at (using the XKCD password): correct horse battery staple : 104.2 bits from 27 char set If as an attacker we magically know "thisphraseisdefinitelynotinthedictionary" is words without spaces, and even assume they come from the 2048 word set (though neither "definitely" nor "dictionary" are in that 2048 word set), then by your formula: log_2 (2048^8) = 8 * 11 = 88 bits of entropy markedly stronger than your example random password's 45.99 bits. And as I noted, "far more memorable", meaning such a phrase could be used by regular folks. 1. Quick entropy check: http://rumkin.com/tools/password/passchk.php http://rumkin.com/tools/password/passchk.php 2. Manual entropy check: http://www.wolframalpha.com/input/?i=log_2%282048%5E4%29 http://www.wolframalpha.com/input/?i=log_2%282048%5E4%29
- vikstrous4 14y agoWhen cracking passwords attackers don't just use brute force. The most effective attacks are ones that exploit human patterns such as leet replacements, capital first letter, punctuation at the end, etc. Concatenated words in all lowercase with no spaces is another pattern that can easily be added to their list and probably already is there, so yes, you can assume that that they will be looking at the space of 2048^4 such passwords.
- Terretta 14y ago
- miles 14y agoThanks for igniting this discussion, Niten. While digging around, I stumbled onto this tool which others might find helpful: https://github.com/lowe/zxcvbn https://github.com/lowe/zxcvbn zxcvbn, named after a crappy password, is a JavaScript password strength estimation library. Use it to implement a custom strength bar on a signup form near you! zxcvbn attempts to give sound password advice through pattern matching and conservative entropy calculations. It finds 10k common passwords, common American names and surnames, common English words, and common patterns like dates, repeats (aaa), sequences (abcd), and QWERTY patterns. Sample results (including Tr0ub4dour&3 and correcthorsebatterystaple) and a demo can be found here: http://dl.dropbox.com/u/209/zxcvbn/test/index.html http://dl.dropbox.com/u/209/zxcvbn/test/index.html
- luser001 14y agoPretty cool tool! My passphrases (omitting spaces between words) get a score of 2. But if I drop the vowels, the score goes to 4 and crack time to 'centuries'. I wonder if this is a good way to create passphrases. Anybody want to chime in?
- deleted 14y ago[deleted]
- tempestn 14y agoOriginally was going to chastise you for typing your actual passwords into a random demo version that could have been modified in whatever way. But since it's all js I guess it's a simple matter to verify it's not transmitting anything. Although I guess it could be some really devious thing where it saves the info in a cookie to be snagged later or some such. Did you check the JS code? ;)
- rorrr 14y agoDon't use phrases. Use one really strong password that you can remember with a tool like KeePass. Generate random long passwords (30 characters) for everything and store them in KeePass. I've recently converted all my accounts to that - my passwords are practically unbreakable, at least with the current tech. I feel way more secure than with the shit I had to memorize before.
- wamatt 14y ago>"I have since seen an infuriating number of people point to it to claim that passphrases are more secure than random passwords. They are not." It appears you have assumed all passphrases must take the same methodological route as outlined in the xkcd comic. However, 'noozle stroodle' has an entropy of 69.303 [1] The above quotation, is a passphrase, and it's more secure than any 7char printable ASCII password. While I accept your argument that not all pass phrases are necessarily more secure than seven lettered passwords, one cannot rightly make the antithetical claim either. The correct judgement is: It depends [1] According to the JS tester, http://dl.dropbox.com/u/209/zxcvbn/test/index.html http://dl.dropbox.com/u/209/zxcvbn/test/index.html
- m8urn 14y agoThe problem with your argument is that you are equating entropy with password strength. While entropy is a valid measurement of password randomness, it is not a direct measurement of how strong a password is. Take the password "vvvvvv.vvvvvvvvvv7vvvvvv" which has terrible entropy yet is very unlikely to be cracked. Why? because a cracker does not know that your password contains only three distinct characters and would still perform a brute force attack based on an assumption of higher entropy. If you are talking about short passwords, entropy is critical in determining the strength of the password, but the true measure of a password's strength is the permutations required to perform a brute force attack. While range of character sets determine permutations, so does the password length. You can make up for one with the other, which is why "vvvvvv.vvvvvvvvvv7vvvvvv" is a very secure password. That aside, I did address more of the math of the XKCD comic here: http://xato.net/passwords/analyzing-the-xkcd-comic/ http://xato.net/passwords/analyzing-the-xkcd-comic/
- jimminy 14y agoI agree with you, but that's not how Randall got the entropy for the comic. His entropy numbers come from NIST SP 800-63[0], for "correct horse battery staple" spaces included. But NIST SP 800-63 has been shown to be invalid in metric for entropy, making the comic's numbers incorrect in real application.[1] [0]: http://en.wikipedia.org/wiki/Password_strength#NIST_Special_Publication_800-63 http://en.wikipedia.org/wiki/Password_strength#NIST_Special_... [1]: http://reusablesec.blogspot.com/2010/10/new-paper-on-password-security-metrics.html http://reusablesec.blogspot.com/2010/10/new-paper-on-passwor...