Xkcd Password Generator
preshing.com
preshing.com
I have well over a hundred websites listed in my password manager. There is not a chance that I could remember a unique password for every one of them, no matter how easy they were.
G#00gl3
A#m4z0n
F#4c3b00k
...
https://www.guildwars2.com/en/news/mike-obrien-on-account-se...
secret () {
# '\u' for `sed` is a GNU extension.
shuf /usr/share/dict/words \
| grep '^[A-Za-z]\+$' \
| head -n 3 \
| sed -e 's|\(.\)\(.*\)|\u\1\2|g' \
| tr -d '\n' \
| sed -e 's|$|\n|g'
}
> for _ in `seq 7`; do secret; done
InterweaveMakariosEncrusting
DisseminatingAgriculturalistCautioned
EffectuatingCobblersEgos
AccidentalKopeckRevolts
RefDivansUndersigns
SalesmanSubmitterFlak
TempsIlluminedQuickening(Limiting the word pool of each slot due to mnemonics would complicate the entropy calculation, but it should still be fairly straightforward.)
I won't deny though that for mobile use, it's a bit cumbersome. The Android app is fine and free[3], and iOS app is a buck[4]. And overall it's a pain if you must login to sites frequently (ideally, using a native app reduces this greatly, login once until you manually logout).
It's also pretty confusing for non-technical people to get behind. I actually sent out an entire email blast to friends and family giving them my best attempt at an explanation, argument, and tutorial of how to use it. I don't think anyone did it.
So while the interface is kind of clumsy, the strategy is solid and I love knowing that I can use it.
[1]: http://www.supergenpass.com
[2]: https://github.com/chriszarate/supergenpass/issues/40#issuec...
[3]: https://play.google.com/store/apps/details?id=info.staticfre...
[4]: https://itunes.apple.com/us/app/supergenpass/id451606360?mt=...
(With thanks to Alyssa Rowan for the CSPRNG design. Public domain - feel free to copy it.)
For really important stuff, actual dice just to make sure.
(See step #6 in the list of steps in the article)
I'm sure the situation has only got worse since then.
Even Diceware, which uses a list of 7776 words, is resistant to attacks if you have a 7 word passphrase.
You use your long random passphrase to protect your password safe. The passwords in your safe are long randomly generated strings of lower case, upper case, digits, and special chars.
> But you’re forgetting the massive GPU array. The hacker runs a program that generates random combinations of two, three or four dictionary words and tries it against your password hash. It’s going to take a while because the number of such combinations are very large, but it’s not impossible. If the hacker is really obsessive about it, he will just keep the program running for weeks until a match is found.
No one today recommends 4 word passphrases - 7 word is the minimum. But 4 words is probably better than most passwords that people use at the moment.
The xkcd comic suggests a combination of four from a very modest 2000 (2^11) common words resulting in ca. 2^44 combinations to check. It also assumes 100 guesses/sec which result in over 500 years to break. That's precise math and a somewhat reasonable assumption.
You counter this with an argument like "the number of such combinations are very large, but it’s not impossible". You give no new numbers, no counter-assumptions, you don't argue that 100 guesses per second is too slow, you just state this.
So in this form your argument is ungrounded.