4 ms·
This feels like more of a solution looking for a problem, to me. Why? Because even if I increase the entropy of my passwords/passphrases for systems I have to
by herghost 12y ago
This feels like more of a solution looking for a problem, to me. Why? Because even if I increase the entropy of my passwords/passphrases for systems I have to use every single day, the vast majority of them are still going to need me to use numbers and special characters, AND make me change the password in the region of every 30-40 days.
Going to all this trouble to generate an admittedly excellently secure password continues to pass the burden of good passwords on to the end user whilst doing nothing to alleviate the core problem, namely that I have to regularly use about 10-20 passwords each day.
My preferred solution is www.passwordchart.com
In this, I select one very good password/passphrase (for which I could use this method) and then I use an indicator of where I'm logging into to generate site/program specific passwords, e.g.,
Phrase: cleft cam synod lacy yr wok
Password: 123facebook321
Generates: yb63476F9xk6RjGVyp6yp6Hj8347b6y (with +Include Numbers ticked)
Phrase: cleft cam synod lacy yr wok
Password: 123twitter321
Generates: yb6347963m6mj963963RjfRd347b6y (with +Include Numbers ticked)
So, for my remembering one complex passphrase and one strategy for generating passwords I can generate strong, complex passwords for any site I need and don't have to remember a single one of them. The only pre-requisite I have to get into a site on another machine from my own is that I have internet access (or have a printed copy of the matrix, or something like that).
(My dependence on this website is the one weak link in this, and I have actually implemented something similar on my own webspace that I just need to tweak usability for a bit before I switch over.)
- ash 12y agoThere are security problems with this idea: 1. Your twitter password leaks information about your facebook password. E.g., "e" is encoded as "Rj" in both of them. 2. If attacker gets hold of your twitter generated password and assumes "twitter" is encrypted somewhere inside, he now knows how you encode "t", "w", "i", "e" and "r" in your other passwords. Numbers are easy to guess or brute-force. 3. It's too tempting to just add a number to password in order to change a generated password for some site. But the generated password barely changes (and remember that attacker could know how you encrypt numbers): Password: facebook Generates: 6F9xk6RjGVyp6yp6Hj8 Password: facebook1 Generates: 6F9xk6RjGVyp6yp6Hj8y
- sarciszewski 12y agoThis reminds me of Passera: https://github.com/mwgg/passera/issues/5 https://github.com/mwgg/passera/issues/5
- peri 12y agoSoftware security is an engineering problem. If your threat model includes the attacker knowing how you generate your passwords (and it probably should for most companies — insiders and disgruntled staff are a big risk), this scheme may not be significantly better than using 1password or a similar password safe on a device you know you/your employees will always have on them. That's not to say you're wrong, it's just that you're making trade offs here like in any other engineering problem.
- ChikkaChiChi 12y agoGood idea. Unfortunately I wouldn't want to be near you when you hit the inevitable "Please provide a password between 8-20 characters" like you see throughout the web. Microsoft is one of the biggest offenders of this issue.