Researchers discovered the perfect password that’s easy to remember
washingtonpost.com
washingtonpost.com
This is my biggest pet peeve. Actually, my second-biggest. My biggest is when registration silently fails because the password was too long.
Relegating you to use a password manager anyway, at which point you might as well just generate random passwords that don't rely on dictionaries?
Just continue to use a password manager, and save the poems for your master password, your ssh key, your unix account, etc. Only then do you need to recall on demand.
People are completely free to use password managers, but that's their individual choice.
Additionally: There are how many songs in existence today? Apparently some tech dude said there are >97 million. [1]
How many of those are lyrical? How many unique excerpts are possible of those lyrics?
You can chose an excerpt of your favorite song as a pass-phrase, and the chance of a computer guessing that is infinitesimal (though this statement is very hand-wavey without any maths to back it up), and it is supremely easy to remember. It's also highly unlikely that you'll ever share it with anyone on the planet, let alone the same site (also hand-wavey).
If you're smart enough to remember more than one song, you can probably build up several pass-phrases that are supremely easy to remember, nearly impossible to guess, and easier to type than some rando-group of characters.
Like I said, you/anyone is free to use a password manager, but I'll continue to prefer other means.
[1]http://www.marsbands.com/2011/10/97-million-and-counting/
There might be >97 million songs, but how many songs does one individual know well enough to decide to use them for a passphrase?
If a lot of your friends are trying to hack you ... maybe stop pissing people off? idk, that's an attempt at humor, but probably not a good one.
A password manager does not have to be a single point of failure. To lose access to my passwords, I'd have to lose my phone, tablet, two computers at home, and one at my office, as well as my offline backups.
> If you're smart enough to remember more than one song, you can probably build up several pass-phrases that are supremely easy to remember, nearly impossible to guess, and easier to type than some rando-group of characters
I have around 400 passwords. That's a lot to remember. Don't forget that not only would I have to remember 400 pass phrases, but I'd also have to remember which goes with which site.
For sites that I have to enter passwords frequently, I could probably keep track, but there aren't actually many sites like that because of cookies.
To make 400 memorized pass phrases work, I'd have to maintain a file with a list of sites and pass phrase hints...and now that file is as much a point of failure as a password manager database would be. Those hints might help an attacker guess my pass phrases, so that hint file needs to be kept secure.
Wait...so now I'd essentially be using an improvised, half-assed pseudo password manager that has all the potential downsides of a password manager, but that doesn't actually remember the passwords for me! That is totally texas [1].
Right now, the best guidance is to only use a memorable password on files which never leave one's physical control, and to use truly-random passwords on remote machines. This is a pain, because it means that one cannot (or at least, should not) back up one's data securely: any encrypted backup would require a password under one's physical control, but the whole point of the remote backup is to recover from incidents compromising one's physical control. It's a conundrum.
This development could be of real use in securing a remote backup of one's passwords: high-entropy and memorable.
I take a passage of reasonable length from a book that I've memorized, could be song lyrics or anything though. Then to create a password I take the first several words to make a password roughly the length I want, do a standard transformation on it that results in a string with numbers and special characters and use that as a password.
When I need to change my password, I just take the next phrase from the passage and apply the same transformation. This has the distinct ability of letting me go back in time and remember what password I would have used at a certain time which has come in handy for remembering the root password on an old server.
Uh...
They went through all the trouble of making a website. Maybe use https and just show me the password on the website?
The "email me a password" service also currently has a note on it that says "Note: Site is super busy! Approximate waiting time: 269 hours."
Which, in turn, implies that some system handles the password as plaintext rather than via a password-appropriate digest.
I memorize the sentence.
My favorite 7 beavers aren't taking to water!
Password would be: Mf7ba'ttw!
It's highly random just like the poems. It's easier for me to remember. It has the right length and random symbols to make the strong password detectors happy.
You tend to say the sentence as you type the password so for bonus points, you can make it a nice motivational mantra.
You're good enough, you're smart enough, and doggone it, people like you.
Y'ge,y'se,adi,ply.
The idea is that people can't use their personal passwords so they fall back on trivial variations of common ones.
For evidence, I've been assembling so called "cracks" and database "leaks" over the past several years and cataloging the password policies on the sites and then doing statistical analysis on the passwords.
It's in interesting project ... check my user info and email me if you want to know more about this
The phrasing of the title made me think of an Onion article along the lines of: They found the perfect password, it's '42Lemons?' and everyone should use it!
What they found is an excellent password scheme for humans.
I thought the same thing. A great example of "what worked for someone else may not work for you".
What people don't realize that professionals who crack passwords for a living use quite sophisticated techniques using known information about the target, common masks, and patterns makes cracking specific passwords easier than just bruteforcing them.
If you use a 300K words dictionary and know or can assume that the paraphrase will be constructed out of 3-5 words the password entropy isn't as large as just thinking this is a single case or mixed case alpha with say 12-16 characters.
When dealing with generic password your basic unit is a character so a 16 char password is made out of 16 units each of those has a specific search space single case alpha it's 26, mixed alpha it's 52, single alpha numeric it's 36 and so on.
Here you have 3-4 units each has a fixed search space and that's the dictionary you use, the search space can be even more restricted if we can assume certain things about the algorithm that generated the passphrase.
If we take the poem example we can assume that words will not appear more than once in the passphrase and that they might need to rhyme this alone can reduce the password entropy considerably.
If we take other examples like story based passphrases e.g. "the quick brown fox jumps over the lazy dog" then we can base our assumptions based on what we know of the English language for example that words like "the" will appear at least once in such sentences as well as take some estimates about how many verbs, nouns, and pronouns will appear on average in each sentence based on their common distribution which allows you again to reduce the search space considerably.
Passphreases are still great when you need to ensure that your passwords won't be broken in bulk when a breach happens because unless your account is admin@ijustgothacked.com you most likely won't be a target and those types of datadumps are still usually broken through basic dictionary, masked and cheap bruteforce attacks.
If you might be targeted directly or phished than passphrases might not offer any sufficient level of protection and could actually be weaker than an annoying mixed-alpha-num-special password.
That of-course will change if everyone will start using passphrases if you expect that 50% of your hashed passwords dump is passphrases you will adapt your password cracking techniques accordingly.
Paper: http://www.isi.edu/natural-language/mt/memorize-random-60.pd...
The password cracking numbers they reference in their paper refers to bruteforcing LM passwords using a GPU by randomly generating characters, using a rainbow table increases that number by several orders of magnitude, using masks and dictionary attacks also increases that number considerably.
Other assumptions like knowing the maximum password length supported by the authentication mechanism you are attacking can make this even more trivial to attack because while their average input is 52 or so chars per poem if you are attacking a system that does not allow more than 36 chars for example you pretty much limiting the password entropy to a few thousands of passwords in their case.
This was an interesting read but it lacks quite a bit of stuff to work in the real world, just like the fact that a 2048 bit RSA keys are in theory almost impossible to factor doesn't mean you can't do that if you can assume allot of things about the key, when you can employ work reducers you start shedding quite a bit of that on-paper entropy.
Obviously if the authentication doesn't allow the password to be entered then the scheme won't work. That's true of any password scheme.
The only real constraint here is every single number must map to a viable poem, and every single poem that can be generated must represent one and only one number. This means the poem is truly just an encoding scheme for the number, and as long as the number is sufficiently large and randomly generated, the poem should be just as secure as the original number was.
And, I would be shocked if the poem constraint takes off more than a few bits of freedom. (Only 1 in 128 words are compatible for your rhyming pair? That's 7 bits. Compensate for it in full by just adding one more word to the passphrase.)
If you apply other restrictions like knowing that the authentication mechanism only allows X number of characters and assuming that the user will attempt to come as close as possible to that max but cannot pass it obviously it allows you to reduce the amount of valid poems even further.
People who are good at password cracking and social engineering can often reduce the amount of possible passwords for a specific target to about 10,000 with quite high accuracy, this is less math and rocket science and more common sense and psychology in this case.
How many possible rhyming couplets are there? I'll give you a hint, it's a huge number.
> and is easy to memorize.
They do this by choosing from a million candidates. That reduces the key space by log2(1000000) ~ 19.9 bits. Compensate in full by increasing the key size by two more words.
> social engineering
Irrelevant. The passphrases are selected by computer.
> to about 10,000
Do the actual calculations.
I think we should held a competition to find out how old this tibit of knowledge really is and also the oldest article about security experts demonstrating passphrases are wide open to dictionary attacks.
1982 reference on passphrases http://www.sciencedirect.com/science/article/pii/01674048829...
Once you see them as tokens that 3rd parties will probably lose, then you know our efforts should be in secure token management software (keepass, lastpass, 1password, etc).
To put it another way, what would you suggest for a master password for the token management software?
Like, what if you pick the corpus of a novel that you've read as your master password. And the password manager uses that novel plus several other novels that you have selected (but didn't read/won't read?) to give you a series of multiple choice selections to determine if you know the right book. Just a few short passages. Preferably with proper nouns stripped out.
You have to select the passages from the correct book for all the multiple choices. That way rather than recall, the memory factor is recognition. Combine it with a non-memorable token which you have to present first in order to even see the recognition factor test and you might have something workable.
number of options * number of questions
This is essentially the same "password reset questions" loophole that allowed the apple cloud storage hack on a bunch of celebrities.
I dunno, just a thought, but do you get what I'm saying about recognition vs recall? Why don't we have the computer test us about things we're good at if part of the test has to be something only our individual brain is capable of?
For now, I guess it looks like a master password, which yes this paper elucidates methods for. But as long as you're memorizing 1 password (not 400), then how you manage to memorize it is of fairly small systemic gain.
Jut generate random password and memorize it, like you memorize other random numbers and strings, like lock combinations, room numbers, car numbers, etc. Learn how to memorize arbitrary long strings of characters and you will have no problems with them for rest of your life.
To make life easier, memorize short password first, e.g. Gc@b%, let call it "alpha", then, when password expired, memorize two new short passwords, "beta" and "gamma", and include your old password "alpha" between them (or rotate it, or flip, or use part of it, etc.), so your password will 2 times longer and stronger. Repeat procedure next time. In short time, you will have list of "words" - short pieces of random strings, which are hard to guess by strangers, but remembered well by you. You can use that dictionary to construct new passwords while keeping adding new random or non-random "words" to dictionary, e.g. "car" - something related to your car, "house" - something related to house, etc. Then your password might look like "alpha-car-beta-house", which is easy to remember by YOU, but hard to guess.
Even if you use the limited Diceware list (7776 words) you get 7776^7 which is plenty.
> Gc@b%
26 upper, 26 lower, 10 numeric, 20 special chars (which are risky to use)
82^5. 3707398432. That's weaker than the 3 words phrase from a 50,000 dictionary, which is a phrase that no-one recommends and that you rejected as being too weak.
Eg 10000^4 or even 1000^4 (for those types who would use "password" otherwise)? Isn't that quite bad or am I understandig something incorrectly?
That's plenty secure for most passphrases, even if the attacker has the exact same wordlist as you do.
FeetFourMonkey
Let's make it easier and assume the diceware list only includes the 26 lower case characters (nothing else), that all words are separated by a single space, that the passphrase contains 7 words. And we assume our attacker knows all of this, and has the same wordlist we used. Heck, we'll even give them our dice too.
How at risk is our 7 word passphrase?