9 ms·
A plastic card for easy to remember strong passwords
- tantalor 12y agoIn general I really like generating passwords like this, but there are some downsides. It is difficult to change it later, e.g., if the password expires or is compromised.
- qycard 12y agoWe've got you covered: https://www.qwertycards.com/frequent_questions.html#lost_stolen https://www.qwertycards.com/frequent_questions.html#lost_sto... Every card ships with a letter showing the only unique copy of the card.
- eterm 12y agoError: EMFILE, open '/home/qwerty/live/views/frequent_questions.html'
- dogma1138 12y agoNice code book but you can just as well print it yourself :D
- mason240 12y agoThis would actually be very useful for my Google and LastPass password. I have everything else in my LastPass manager, but it is always trying to get into my google account from different places is difficult, so I have a rememberable password for both. This would let me keep a much more secure password for both.
- chronial 12y agoJust use random words. Memorable passwords don’t have to be weak. Five random common english words are already very strong. Just make sure you don’t pick the words by hand.
- sarciszewski 12y agohttps://github.com/resonantcore/lib/blob/master/js/diceware/diceware.js https://github.com/resonantcore/lib/blob/master/js/diceware/... https://github.com/resonantcore/lib/blob/master/demo/diceware.html https://github.com/resonantcore/lib/blob/master/demo/dicewar... Run this locally, e.g. dw = new Diceware(); dw.load("https://raw.githubusercontent.com/resonantcore/lib/master/js/diceware/diceware.wordlist.asc", function() { console.log("Diceware loaded!"); }); console.log(dw.getWords(8).join(' '));
- __david__ 12y agoIf you're on linux you can usually just do: shuf -n 5 /usr/share/dict/words On Mac OS X you need coreutils for shuf, which you can get from brew (it's called gshuf once installed).
- anonfunction 12y agoTo get rid of the newlines shuf -n 4 /usr/share/dict/words | xargs | sed 's/ //g'
- __david__ 12y agoOr slightly more simply: echo `shuf -n 5 /usr/share/dict/words`
- sarciszewski 12y agoMaybe add this to your .bashrc file? randword() { if [ -z $1 ]; then echo `shuf --random-source=/dev/urandom -n 5 /usr/share/dict/words` else echo `shuf --random-source=/dev/urandom -n $1 /usr/share/dict/words` fi } Test output: kobra@stormforge blah $ randword 4 crackpots fragmentation maximally Bradly's kobra@stormforge blah $ randword 6 turnover's nonproliferation's bestowal's sulkier hillbilly Narmada kobra@stormforge blah $ randword Marciano fibulas roadwork mobilizations organics kobra@stormforge blah $ randword coins bronzed housemother's forefather supposing
- bkeroack 12y agoFine idea if the codes are generated randomly for each person. Do not use the same card as someone else. Or you could use something like (one of my side projects): https://www.wordentropy.org https://www.wordentropy.org
- agwa 12y agoThis is a substitution cipher and it's not very secure. Consider what we can do if we compromise the Amazon password that's given as an example on the website: sh(/J3HqAfQsu..u.rqf Since the password came from Amazon, we know that the last 6 characters are "Amazon," which tells us that: . = A u = M r = Z q = O f = N Now we can start attacking the codeword, which are the characters between the 8-character "space bar code" and the website name: AfQsu. Using the letters we already know, we can determine that the codeword is: _N__MA It's probably a dictionary word, and we know that the blank spaces don't correspond to any of the letters we already know. According to the following command: grep '^[^amzon]n[^amzon][^amzon]ma$' < /usr/share/dict/american-english ...the only possible codeword is "engima," so now we know that: A = E Q = G s = I Combine with another compromised password, and we're coming dangerously close to being able to generate a password for any arbitrary website. Edit: I agree with the replies that this is an unlikely attack considering how passwords are typically compromised. And it's probably better than how most people choose passwords. But the website claims that this generates "very strong passwords," which is nonsense.
- advisedwang 12y agoThere is no need to even break the codeword as it is the same for every site. In the above example say we want to guess their gmail password, it is probably: sh(/J3HqAfQsu.?u.?? We have only three characters to guess! OTOH this is only relevant for targeted attacks where the attacker has one password. This still protects you pretty well from bulk attacks (so long as the card is not widely used) and is miles better than re-used or poor passwords at little usability cost.
- agwa 12y agoWith the codeword broken, we can narrow the gmail password down to a single unknown character! sh(/J3HqAfQsu.Qu.s?
- johnnymonster 12y agoThe site is only an example. You would actually order your own unique card to carry with you. No one would be able to guess your password since your spacebar code is unique to your card.
- beering 12y agoThis is a lot like PasswordCard[0] except not free. [0] https://www.passwordcard.org/en https://www.passwordcard.org/en I think I'd like PasswordCard because it's pretty freeform - just pick a starting point and a visual direction/pattern and copy letters from the card. But honestly I don't much like the idea of relying on a physical token if I don't need to. Almost losing my 2FA last year was a bit scary.
- detcader 12y agoPasswordCard does give you a seed number to generate the same card, though..
- bigbugbag 12y agoWhich is not really a problem because having the card does not give away the scheme used for a particular password. Qwertycard on the contrary exposes their recommended scheme publicly which make losing the card a much higher risk of compromising your password.
- patrickdavey 12y agoI actually really like this idea. I guess if your attacker did get your password in the clear (bad encryption or whatever) then they'd basically have access everything right? I mean, the number of letters at the start is presumably fairly constant, they'd know the site it was for so they could then work out the "unique secret" in the middle right? That said, there's a certain amount of security through obscurity I guess. Still, for any of the sites I really care about I use two factor authentication. I'd take a mediocre password and 2FA over a strong password (But happy to be proved wrong ;)
- sago 12y agowhy would anyone need to know your secret? Except that it would give them more characters in the substitution cypher. The card assumes a user will keep the same secret for each site, so just keep the start of the PW the same.
- stevewilhelm 12y agoWhat prevents me from using this type of strategy is the inconsistent adoption of password requirements. For example, some of the websites I use require passwords to contain at least one capital letter, or a digit, or a punctuation mark (e.g. ! ? #, etc.). But other Website do not allow punctuation marks or digits. Some require a password of a minimum length, but a dwindling few can only accept fairly short maximum length password.
- bro-kaizen 12y agoWait really? It feels like almost every time I make a new account somewhere and drop in the 200 character high-entropy password that LastPass generated, I get a silent failure or misleading error message about "your username was not recognized." Then I try guessing which feature of my candidate password is pissing off the site: Is it the whitespaces? Special characters? Length? This is particularly maddening because there are plenty of ways to accept arbitrary passphrases from users.
- jrockway 12y agoYou use 200 character passwords? I'm happy with 12.
- Springtime 12y agoObviously the longer the maximum available length the better but it does assume the host computer always has the password manager installed. I'd shudder to think how such a long password would be entered otherwise.
- Dylan16807 12y agoOnce you get up to a threshold like 128 bits there's no real benefit in going further. So 22 alphanumeric characters is 'good enough for anyone'.
- gravedave 12y agoSo what this site is essentially selling is a single run of a random number generator printed on a piece of plastic and a 3-step process?
- samspot 12y agoExcept it's not going to work, because of the bank who doesn't allow '(' as a special character, or the ticket website that requires at least 3 digits, or the financial firm who only allows 8 character passwords. As soon as you have a few sites with 'rogue' password policies, the system breaks down.
- gravedave 12y agoThere are ways around it: using the code for the key directly north-west of the problematic character, and if that's a bad character go further, maybe wrap around, or try to follow through the problem character (a/& -> &/| -> |/f, thus f would be the code for a) etc. As for remembering which sites have what restrictions, I can keep that stuff in my head (looking at you Microsoft), but I guess you may have more accounts than me. Then again, when a password fails, then all you'd have to do is retry with a safer version (and maybe only have two password kinds, for convenience - full-blown char support, and minimalistic lowercase-letters only, so you'd only have to retry a single time after the first failed login). Personally, my biggest problem with this card is that it doesn't provide enough value.
- cplease 12y ago> Then again, when a password fails, then all you'd have to do is retry with a safer version And after three or five failed login attempts you get locked out and have to call the bank for a password reset, and throw away the damn card in frustration. > (and maybe only have two password kinds, for convenience - full-blown char support, and minimalistic lowercase-letters only, so you'd only have to retry a single time after the first failed login). If you're authenticating with more than HN and Reddit, you'll encounter much more than two mutually exclusive password policies.
- danjayh 12y agoI tried going to a similar algorithm of my own invention some years ago, and ran into this exact problem. Mostly sites that don't allow certain characters (which is asinine). Now I have a few different algorithms that I use that are friendly to common password requirements, and I keep a list of which algorithm I used on each website, rather than just a list of the passwords. Since the algorithms only exist in my head, I think it's secure enough for most purposes.
- w8rbt 12y agoThese others have been around for ages. And, they are free. http://www.passwordcard.org/en http://www.passwordcard.org/en
- scenefinale 12y agoI use dvorak, you insensitive clod!
- raarky 12y agomy current "scheme" for creating new passwords is to simply write a long, unique passphrase with the idea that I will only remember it for the short time needed to log in after registration. If I need to log in sometime in the future, I simply reset the password.
- theophrastus 12y agoSome of us have even made do with variations on the "Old School Tabula recta": http://lifehacker.com/5715794/how-to-write-down-and-encrypt-your-passwords-with-an-old-school-tabula-recta http://lifehacker.com/5715794/how-to-write-down-and-encrypt-... "If I'm logging into Amazon I'll find the intersection of column M and row A (the second and third letters of Amazon) and then read off diagonally 16 characters."
- lifeisstillgood 12y agoSadly this is still a fail - I have found numerous sites whose fatuous restrictions on what are or are not legal entries include banning punctuation, never ending in a letter and more. This seems an amusing and useful idea to making passwords - it's usability seems longer lived than my previous (personal) attempts (md5 hashing passwords and domain names). In the end I need a trustable approach to storing encrypted data on my iphone - I suspect i have missed one. Any ideas?
- JTxt 12y agoI use "FileBox" for some things, but I'm taking the developer's word that it is secure.
- zokier 12y agoI don't believe in these sorts of database-free password management systems. These require users to remember too much stuff and are not flexible to be used universally. And using these gets only more painful over time as exceptions etc accumulate. These issues have been discussed fairly comprehensively in the various HN threads on hash-based password managers, which share most if not all the downsides with this particular project.
- jnellis 12y agoI have just as hard a time remembering my usernames as I do passwords.
- jaynate 12y agoCool solution for folks like us. Best way to diminish password as an attack vector and secure services for the thronged masses is to reduce the number of passwords required to use the Internet. And couple a master (eg My google account) account with a second, biometric factor.
- docubot 12y agoThat's all well and good until you lose it or run it through the washing machine. Then your entire password system is gone. Any backup would need to be stored in a place that might as well be your 1Password/LastPass database.
- Animats 12y agoWho has access to the "random" info on those cards? How randomly are they generated? If you bought a few of them, could you work backwards to the generation algorithm?
- Sir_Substance 12y agoBrilliant! Until you lose your wallet. Much like lastpass and other password management software, you're putting all your eggs in one basket, and having faith it won't fail. Passwords are a shitty idea people. We need a better system.
- krapp 12y agoAny authentication system will (and should) fail if you lose the authenticator. That's not "shitty", that's the way it's supposed to work. A better system, to be of any value, would fall prey to the same 'weakness'. Even biometrics can change over time.
- canes123456 12y agoMath/Crypto allows for distributed authentication. Think bitcoin block chain, miners verify each transaction and but it doesn't rely on any single miner.
- bigbugbag 12y agoThe bitcoin blockchain relies on the assumption that the mining power is honest and no single entity will hold the majority of the mining power. This has proven to be an issue with the selfish miner case and when a single mining pool reached 51% of the total mining power. In the world of security you simple cannot assume honesty and build security on top of this assumption.
- Dylan16807 12y agoIt's not two factor, so no it's not 'supposed' to fail if you lose it.
- cenhyperion 12y agoYou could take a photo or photocopy of that and leave it in a secure place. Boom, backup.
- marssaxman 12y agoPeople keep saying that passwords are a bad idea, but what else is there?
- mingabunga 12y agoLooks a bit like http://passwordlive.github.io/ http://passwordlive.github.io/
- biggot_man 12y agoThis idea is useless. You could just use keepassx or any other password manager. Easy to use, and copy paste friendly.
- izolate 12y agodamn, edgware is the last place I'd expect to find a tech company. cool concept though. do you sell these out of your office too?
- crazygringo 12y agoBesides other problems (like not working with certain password requirements), this particularly doesn't work when a site forces you to reset your password because of a breach or time limit or who knows what. (Yahoo just forced a mandatory password reset on me today, without even giving a reason except to "protect my account".) Then you've got to remember -- are you now on amazon3 or amazon4 or gmail4 or gmail5? And then it defeats the whole purpose of the card.
- z1mm32m4n 12y agoIf the end goal is to turn a long, comprehensible password like "correcthorsebatterystaple" into something not remotely subject to a dictionary attack, then merely shifting your fingers over on the keyboard by one key is much more convenient: "vpttrvyjptdrnsyyrtudys[;r". Sure, it suffers from the same short-comings as mentioned above (it's still a substitution cipher), but it's much more convenient than going to the card for each individual letter. "vottrvyjptdrnsyyrtudys[;r" is as quick to type as correcthorsebatterystaple but much™ more™ secure™.
- bigbugbag 12y agoThis is a simple variation that I have not seen covered in hashcat, though it is not future proof. If people catch on this then it won't be long before a new rule is added to hashcat to cover this case. I have used a similar variation in the past, in my case the character substitution came from changing the keymap of the keyboard. for example 'correct' typed in qwerty over a dvorak keymap became 'krpp>ky'
- b_white 12y agoIt's rather ironic this site is all about strong security, when their SSL/TLS settings are terrible. (Including being open to the POODLE and OpenSSL CCS vulnerabilities) https://www.ssllabs.com/ssltest/analyze.html?d=qwertycards.com https://www.ssllabs.com/ssltest/analyze.html?d=qwertycards.c...
- ninjakeyboard 12y agoI just registered dvorakcards.com and colemakcards.com. Thanks,
- gnerix 12y agoMany sites where I perform sensitive transactions require me to periodically change my password (banks, brokerage, etc.) The Shannon entropy of the impossible to remember example password is 3.68418, which is not much better than the xkcd "easy for a human to remember" password 3.36386
- alejohausner 12y agoHow about doing Vigenere in your head? This is what I do: I actually write my passwords down in my little black book, which I carry in my pocket. I use a simple Vigenere cypher in case I lose the book. Each password is encrypted with the same master key, which I memorize. For example, if my master key was 1234, and my password was 'baNana3', it would write down 'ayKwmy0'. When I look up the password, I shift the letters forward as I type them: a + 1 = b y + 2 = a (wrap around the end of the alphabet) K + 3 = N w + 4 = a m + 1 = n y + 2 = a 0 + 3 = 3 It's not too hard to advance 9 or fewer letters in the alphabet as you type. I think i'm safe. Am I?
- A1kmm 12y agoIf you physically protect your book sufficiently and don't let anyone who is a threat see it, and choose strong passwords (which baNana3 isn't for most purposes - it's only 7 characters long, and based on a dictionary word with minor modifications) then yes. If someone willing to put in the effort to do some cryptanalysis obtains a copy of your book, then no, you are most likely not safe. Firstly, the Vigenere cipher is extremely vulnerable to a known plaintext attack on the key - if the person who obtained your book knows your password to just one site (for example, because it was lost in a compromise and published on the Internet), they can work out your master key and then get all your other passwords. Even if they don't know any passwords, if you use passwords that are not made up of equiprobably randomly selected characters (and especially if they are dictionary words), the attacker will usually be able to use that bias to work out the master key. For example, the attacker might cycle through all words in the dictionary to obtain the key that decrypts aykwmy to the word, and try the master key they obtain on other entries in your book until they find one that yields a lot of other dictionary words.
- bigbugbag 12y agoThis is a poorly thought out (qwerty only ?) and weak security attempt to make money ripping off the concept from the much better and secure password card at https://www.passwordcard.org/ https://www.passwordcard.org/ that anyone can print themselves.
- johnchristopher 12y agoAre each card produced with a different substitution pattern ?
- trymas 12y agoI'll just leave this right here: http://xkcd.com/936/ http://xkcd.com/936/
- midnitewarrior 12y agoWhat about trust? Who is selling me this card, and with my name, address and (optional) email address, how long will it take him to crack every one of my accounts, considering that he has the key?
- enjikaka 12y agoI did a web version: http://codepen.io/enjikaka/pen/zxNMQZ http://codepen.io/enjikaka/pen/zxNMQZ EDIT: Just changed alot of things so if you viewed this in the last couple of minutes... take another look!