8 ms·
So this is very interesting. It's not exactly a strength estimator (note that Microsoft isn't calling it one, Bruce Schneier is) because it doesn't really retro
by DanielStraight 13y ago
So this is very interesting. It's not exactly a strength estimator (note that Microsoft isn't calling it one, Bruce Schneier is) because it doesn't really retroactively evaluate the whole password. For example, "Entrolax" passes the test even though it's the name of a drug and therefore likely in dictionaries used for attacks. It passes though because the letter sequence is sufficiently strange. Similarly, the relatively unobscure "omnipresent" gets 4 checks for the same reason.
This also seems to discourage passphrases because even though any good passphrase (such as "correct horse battery staple") will get 5 checks easily, you have to get through a lot of Xs to get to those checks, each one suggesting that what you are doing isn't a good idea.
The tool does however suggest an interesting alternative to passphrases: Only use as many letters of each word as are unpredictable. In other words, only type each word until the next letter is predictable. For "correct horse battery staple" this gives "c h bat stap". I really have no idea if this is a good password, but it does get 12 out of 12 checks and only one less check than the full phrase.
As with any password evaluation, there are patterns it doesn't know how to check. It takes a long time to figure out the pattern "a1 b2 c3 d4 e5" and still gives a check for each space. It doesn't detect spiral patterns on the keyboard at all ("gtrfvbnhy" on a qwerty keyboard for example).
Still, it will be interesting to see what they can do when they get more data and think through some of these issues.
EDIT
You can also use this to choose letters that make sense but aren't in the prediction. I came up with the password "pitabakes" (pita bakes), which is obviously pretty easy to remember and presumably fairly weak simply by deliberating taking something which seemed likely but not in the top 3.
One also has to wonder whether deliberately being unpredictable somehow becomes predictable. This tool, to some extent, suffers from the fundamental mistake of gamblers: seeing patterns where there aren't any. See jerf's post about getting X marks in a LastPass-generated password. If you tweak your random passwords to not be predicted by this engine, are you actually making them somehow more predictable?
EDIT AGAIN WITH MORE NEW FINDINGS
You can also get high numbers of checks (and a relatively high ratio of checks to X marks) using common dictionary words if you switch words in the middle. So, taking the words "grape", "pasta" and "toffee", using "grapastoffee" which gets a 50/50 ratio of checks to X marks (6 of each). This actually seems like a pretty good way to generate hard to guess passwords. "Pen", "noodle" and "duck" giving "penooduck" does even better, 7 out of 9 checks.
- Tloewald 13y agoAgreed. Fundamentally, picking a cutoff of "not one of the top 3 guesses" is part of the problem. I'd suggest that not being one of the top 16 guesses (i.e. less than half a byte of entropy) would be obvious the threshold.
- ye 13y ago"correct horse battery staple" is actually not good. It's made up of 4 very common words. So the complexity to bruteforce is around 10000^4 = 10^16 ≈ 2^53.15 So only 53 bits of security. I wouldn't protect something like bitcoins with that.
- fpgaminer 13y agoWhat is your criteria which states that 53 bits of entropy is not good enough? 53 bits of entropy shoved into modern PBKDF2 (10,000 iterations) would require ~11,000 days to brute force on a machine doing 1 trillion PBKDF2 iterations per second. So yeah, a randomly selected passphrase chosen from a pool for 10,000 words would work just fine. Assuming we're talking about secure software. For websites, use a password manager and then pick your poison for how you pick the master passphrase.
- ye 13y agoYou're assuming all your important software does that many iterations. In reality you'd be lucky if all of it does one iteration. In which case it will only take a day on one machine. You're also underestimating how massively parallel GPUs are becoming. The more important question is - why settle for 53 bits and worry about it?
- fpgaminer 13y ago> You're assuming all your important software does that many iterations. Trust nothing. KeePass let's you choose the number of iterations, and can autocalibrate. I believe it calibrated mine to >1mil iterations. I use KeePass to generate the passwords for pretty much everything else, except TrueCrypt (which uses ~1,000 iterations, but it's far more complicated than that). So the number of iterations everything else does is unimportant. > You're also underestimating how massively parallel GPUs are becoming. I'm a Bitcoin miner and developer. I know exactly how parallel GPUs, FPGAs, and theoretical cracking ASICs are. Only ASICs would be able to achieve 1 TH/s of cost effective cracking power, which is where I spec'd my estimate. Suffice it to say, that number I quoted is an underestimate; it would take a real attacker much, much longer. Unless we're talking about organized crime or the government here, in which case you can look forward to them spending a year of their entire computational power on just little ole you. > The more important question is - why settle for 53 bits and worry about it? That is why I asked what your criteria is. A line must be drawn somewhere. Humans aren't good at generating and/or memorizing passphrases. So picking a reasonable threshold is important. If 30 years of security against an unreasonably powerful attacker is not enough, what is?