The password “ji32k7au4a83” has been seen over a hundred times
twitter.com
twitter.com
Within those 2 minutes some chinese hacker scripts took over the server and started DDosing some chinese IP adresses. We had to shut it down and blast it and set it up from scratch again.
I later found out that this password was everything but random. It was difficult for me to see because I've been using Dvorak for a couple of years now and didn't see the pattern that it was just the first two rows of the characters on a qwerty keyboard. So actually it was !qaz@wsx (I just put the Dvorak version on top of the comment to give you the same unknown feeling for the password which I had back then.)
I've never reused any passwords since then and always create new ones with my password manager.
I use colemak so I had neither any idea...
Great narrative trick.
Bravo, Keyzer Soze.
edit: damn, too late I can't change it anymore.
I've had users use parts of lesser known poems or stories in some foreign language, because who would expect that, right? Turns out that's not what's relevant to a good password but rather whether it is in any available corpus.
If your passphrase consists of something likely to be in wikipedia you are guaranteed to get owned in minutes.
Now that I think of it, a non pirated OEM windows key would have made for a great password. ;)
Yeah, I had that one committed to memory in highschool.
It's like saying "My password is the first 10 characters of a really popular book about wizards" and expecting no one to figure it out.
Then consider that this is Hacker News, and how many of those 5,000 have both the skills and motivation to exploit the information you've provided.
Never give out "hints" about your password. Not its contents, not its exact length, the physical location in which you store a copy, nothing.
_Taps side of head with index finger_
Unless there's something fundamentally wrong with the password, a public length of n is almost as secure as a secret length of n, and significantly more secure than a secret length of n-1
Never get into the specifics of a password, but explaining the basic structure should be a tiny impact and well within your margin of safety, or you didn't make a good enough password to start with.
Good luck (Tell me how and where I can make this stronger)
Make it 8193 characters long, change it every 27 days at 11:04am, but most importantly: use it on exactly 0 websites.
Good luck
So whether providing your length is a tangible security leak or not is essentially a function of the size of your character pool, because if your password is short enough for n-1 to contain a significant percentage of possible combinations then it's probably already short enough to brute force anyway.
A good way to look at it is to measure the password in bits of randomness. At most, revealing length can shave off one bit. For any reasonable character set it shaves off a small fraction of a bit. And one bit does not make the difference between good or borderline or bad.
If you worry about any speedup in password cracking that is less than an order of magnitude, your password was too close to failing to start with. Make your password 5% longer, which will make it at least 20x slower to crack, and then you won't have to care if "20x" gets reduced to "15x".
You may say "It's not harmless to give up 25%. What if I give up 25% several times? That could make even a good password become insecure." but there's a limit to how much speedup someone can get from knowing the structure of your password. And the best way to evaluate the strength of a password is to assume that all the structure is public. So I can say that my typical passwords, being 20 mixed-case letters and numbers, all have a security of 2^119. It's possible that an attacker that uses the wrong algorithm would have to guess even more, but I'm not just worried about a clumsy attacker, I'm also worried about a moderately-high-quality attacker. It's a bad idea to depend on that extra .1 bit I could get with this character set, or that extra .4 bits I could get with a smaller character set. Just assume the length is known.
And that's fine, we can have different opinions on that part.
But "probably already short enough to brute force" is definitely not right. That percentage depends entirely on character set, not the length of your password. If your password is just numbers, then n-1 always has 10% as many combinations, whether your password is 5 characters long or 200. If you meant "probably already weak enough to brute force" that's not true either. Lots of passwords with mixed case and numbers and symbols are very short and pretty weak. Lots of passwords with only letters are very long and quite strong because they're made-up phrases. You can't guess the strength of a password just by knowing the percentage of [length n-1 combos] / [length n combos].
But we don't seem to be resolving anything so I'll just hope you have a good week.
Please point to the part of my statement which reflects this idea.
This seems to say that a small character pool, aka "n-1 containing a significant percentage of possible combinations", implies that your password is "probably already short enough to brute force".
So small character pool means that "probably" the password is short/weak.
I'm saying that a small character pool does not imply that a password is "probably" short/weak.
And to be very clear: Using the size of the character pool to say it's "probably" weak is a form of "reliably predict[ing] if n is sufficient".
What am I misreading?
> So small character pool means that "probably" the password is short/weak.
I really don't know how you came to that conclusion. I never claimed any dependence between the character pool length and password length. They're obviously completely separate properties.
Right?
That percentage comes entirely from the character pool.
So character pool -> percentage -> probably short enough to brute force.
What am I reading wrong? The only assumption I made is "compared to a password with length n", because what else would you be comparing length "n-1" to. Otherwise it's a direct quote.
I'm shocked by this subthread!
I probably used the same key to setup over 1000 PC's when I worked there.
https://www.godaddy.com/domainsearch/find?checkAvail=1&tmske...
https://domains.google.com/m/registrar/search?searchTerm=fck...
I guess people on here are 30-ish, so it happened 15 years ago in the 00s. This hints strongly towards WinXP, which has a few famous leaked Serials.
https://www.urbandictionary.com/define.php?term=fckgw-rhqq2-...
I've seen the above but for some reason mine was more prevalent in my region. Common enough that even my friends could recite it.
bound by the power of cerealz
Ensure you specifically permit loading jQuery from cloudflare.com, and check network traffic using a test password first.
Once a friend shared with me one of those services, he got surprised when I raised my concern about compromising his password, he took a second to check the developer tools to see if there was any request including his password, there wasn't, so he called me crazy (it's well known that malicious sites behave differently on certain conditions, one is having the developer tools opened).
Anyway, I suppose that this blind trust is what makes phishing attacks so effective.
I had always wondered if they do, and I've known it's possible, but this is the first time I've heard any accounts of it. Would you have more info on this?
There are many ways to detect it's open (eg. https://github.com/sindresorhus/devtools-detect) and it's also possible to mess with it without knowing it's open. A method that's wildly used is firing the debugger break command many times a second, along with other stuff that makes using the tools nearly impossible (slows the browser down to a halt)
It seems like a huge oversight to not detect ad blockers and let the user know that their password is being transmitted in plaintext if that's true...
turns out 204 other people can too! (though apparently not in all caps)
never used it as a password but i can see why one would
I had to replace the card a few times, but only the first number stuck.
When I was a kid I didn't understand why Sim City 4 Deluxe played after install but didn't play when I stuck disk 2 back in and clicked the game. It was my favorite game for a number of years and it wasn't until at least 2 or 3 years in I realized it wanted me to stick disk 1 in for the copyright protection and that disk 2 just worked during install for convenience reasons. I had been uninstalling the game every night before I went to bed (preserving saves!) and reinstalling it every day after school. One day I couldn't find the case with the key (probably got thrown away) and I thought I was going to have to buy it again but when I went to the computer I was able to get it first guess.
Been 15 years now. I suppose I'm never going to forget that key.
You aren't fooling no one, might as well just say it.
Typing that out on a zhuyin keyboard gets you: ㄨㄛˇㄉㄜ˙ㄇㄧˋㄇㄚˇ
In Pinyin that is wo3 de mi4ma3
Or in English "my password"
I am wondering if it was modeled after Hiragana/Katakana during Taiwan's colonial period?
https://zh.m.wikipedia.org/zh/%E6%B3%A8%E9%9F%B3%E7%AC%A6%E8...
But it wasn’t created by/for Taiwanese specifically, by that time Taiwan was under Japan’s rule and they were learning Japanese at the schools. Indeed it was imported back into Taiwan when KMT fled there.
PRC then went on its own jounery of inventing its own Romanization scheme for Chinese. They once almost chose Cyrillic alphabet because its ideological alliance with Soviets, but Latin script still won at the end of day, because the scholars were convicned it is more widely used and more useful.
[0]:http://img1.gtimg.com/news/pics/hv1/74/203/2056/133743239.pn...
Many cultures that borrowed Chinese characters developed their own ways of simplifying them. Moreover, Chinese characters themselves are composed of distinct radicals, so it's rather natural to try to decompose them when needed. The radicals are ancient, but they can look very similar to kana in their simple forms. This could be an example of parallel evolution, not one borrowing exclusively from another.
It's a system introduced by the Republic of China, and tha continues to be used in the Republic of China (only Taiwan left these days).
That's because the mainland switched to Pinyin in the 50s.
That being said, Taiwan has now also officially switched to Pinyin so use may increase.
Edit:
Another interesting, and old, system to write Mandarin using the Arabic alphabet: Xiao'erjing: https://en.wikipedia.org/wiki/Xiao%27erjing
Edit 2:
Bopomofo is in the same line as Hiragana/Katakana/Korean system: It simplifies and make things phonetic but still creates a brand new characters set inspired by Chinese characters.
With Pinyin, to me the main development was to integrate that there was already an ubiquitous alphabet in existence, the latin alphabet, that could be used and save the trouble of yet another writing system.
A bit like what happened in Vietnam (though obviously that's because a Frenchman came up with the system).
You see bopomofu is to denote pronunciation not to romanticize characters. If you are talking about how location/street names are spelled, some form of pinyin (literally means spelling) had always been used for romanticization.
Hopefully they don't switch to pinyin, and I especially hope they don't switch to Simplified.
Wikipedia says it was created under the Beiyang Government so no. Also bopomofo is an alphabet (seperate characters for consonants and vowels) where as katakana/hiragana are syllabaries
However all three systems are derived from regular Chinese script. Hiragana is derived from cursive Chinese script, Katakana from radicals used as shorthand for certain characters, and Bopomofo from archaic forms of modern characters.
However, I am concerned at how the OP got the string in the first place, that he compared to HaveIBeenPwned? Is he storing his user's passwords in plain text in his back end database, and decided to run them all against the service?? That in and of itself is a security red flag.
This is a rude phrase that probably most Taiwanese understand.
It's just more comfortable that way.
It's just interesting to me, another reminder that physics is just that much more easier than anything else.
It's really just a state you, the observer, can distinguish. This would typically involve things like pressure, volume, and temperature but if you developed a new way of measuring the properties of a system suddenly the possible macrostates multiply in number, each contains fewer microstates, and the entropy of the state decreases. Take this far enough and you could create a Maxwell's Demon to extract energy from thermal motion. But while it's subjective in some sense it was later shown that our subjective knowledge of the world is limited by the laws of physics in other ways and perfect subjective knowledge is impossible.
So you could say that entropy is a measure of your ignorance about the exact state of the world, which corresponds nicely to the information theory definition. It's just that in physics everyone is in practice going to be using the same pressure, temperature, and volume measurements while in information theory what constitutes a macrostate is very fuzzy.
Such a statemenrs make me nervous.
In the late XIX century physics professors told their students that they should stop learning physics and go to some other science, because physics is almost complete. It explains almost everything there are some small issues with electromagnetism which will be solved in a few decades and there would be no more work for physicists. No more physics as a science, just engineering.
At that time physics seemed much more easier than anything else. Like it seems now for you, I suppose.
Though maybe there would be no more Einsteins, and physics really explained almost everything for this time.
Compare particle physics to cell biology, for example. Of course the first has complicated math and a lot of ressources thrown at it, but in essence these isolate the thing to measure. How would you even do that with cells?
A vacuum or laser lab may be complicated or finicky and capricious to work with, but it is nothing compared to a bio lab and the influences on the organisms you try to study.
At least bosons don't react differently when you look at them funny or with the time of day (we assume). (addendum: Like lab mice that change massively depending on the handlers.)
ie., I take probability to be only an epistemic description of confidence given information. And therefore randomness just a lack.
A physical system may be "ontologically random" in the sense that there is no info its possible to obtain to make a determinate prediction -- but that isn't randomness (which is epistemic).
That's "physical informationlessness" which is an (alleged) feature of a physical system that leads to n "inevitable randomness" in our predictions of it.
In China they just use pinyin, so I was baffled as to how ji32k7au4a83 could represent 我的密码. Turns out it's the keys you press if you have Taiwanese input.
It's a bit sad to see how people in a position to formulate password suggestions on a register form can fail so hard at realizing that a uniform transformation of a dictionary word will still be prone to dictionary attacks.
"How to set up a safe and easy to remember password"
reveals:
http://www.netqna.com/2014/05/do-not-set-up-weak-password.ht...
"4. Using Chinese input method:
For example, the phonetic input method of the four" (I guess in Chinese, op. acqq) "words "My Password" is the combination of "ji32k7au4a83"."
Sure, safe. Just for you and everybody who read that. No problem at all.
And some user of some gaming(?) site used it for his username:
Using the above principles, how can we design a good password?
Tip 1: Replace characters with ones that sound the same
For example, you can replace the letter e in succeed with the number 1 {note this sounds the same in Mandarin}, so that it becomes succ11d, which is easy to remember and combines numbers and letters.
Tip 2: Replace characters with ones that look the same
For example, you can replace the o in dog with 0 and it becomes d0g. It mixes letters and numbers.
Tip 3: fill with special symbols
For example, the above password d0g is not long enough, so you can add special symbols at the end, e.g. d0g!(!(!(!(!(!(, it will be easy to remember, but hackers will need 12,340 centuries to crack it.
Tip 4: Using Chinese input method
For example, the phonetic input method of the four words "My Password" is the combination of "ji32k7au4a83". At first glance, it is a random combination, but it is meaningful.
Pretty hilarious all around, anyone checked if d0g!(!(!(!(!(!( is in the database too?
I just checked and... looks like it's not been seen by HIBP:
>Good news — no pwnage found!
>This password wasn't found in any of the Pwned Passwords loaded into Have I Been Pwned. That doesn't necessarily mean it's a good password, merely that it's not indexed on this site. If you're not already using a password manager, go and download 1Password and change all your passwords to be strong and unique.
All those annoying rules about required character classes are mainly there to prevent dictionary attacks, but "s3cr3t" is not much of an improvement over "secret" ("s4cr5t" would, because it's not the result of a popular transformation).
I think it started in "black twitter". People would post jokes and it one of them took off they'd post a link to their SoundCloud page asking people to check out their "mixtape". Others started joking that they don't have a SoundCloud, but check out my book/art/Ruby package/craft beer.
[0] http://www.un.org/en/universal-declaration-human-rights/inde...
I don't see that happening at all. I find this whole activism trope a dangerous game, they indoctrinate each other with a mindest to disregard empirical data and disrespecting authorities put in place by governments.
> do things like prevent cisgender men and women from using anything other than unisex bathrooms
I'm pretty convinced that where I live you can use whichever bathroom you like, while dressing like the unicorn you are. I'll still be using a urinal, though, because I don't want to make a mess for people, cis or not cis, that need to use the bathroom for more serious business.
> infringement against trans people, specifically
I condemn violence, especially against one-legged single-parent dwarves. They deserve better and you damn well know it.
Yes, I use a password manager too, but an ancient one that has no Internet connection, no syncing, and no cloud storage.
The only "modern" password manager I've been able to find that works completely offline and is open source is KeePass -- so long as you don't install any of its plugins that open it up to Internet access.
Kind of a secondary master password that's not stored anywhere except my memory and my safe.
Best of both worlds in my opinion.
A great thing about password managers is that you can change your passwords more often since you don't have to bother coming up with and remembering new passwords. It can even be somewhat automated with pass-rotate: https://github.com/ddevault/pass-rotate
While I agree that this would be a security disaster, its not a whole lot different then someone using the same credentials for all their accounts. Also, one of the great benefits of a password manager is that they remove a very high mental cost of passwords. Before I used a password manager, although I knew it was good practice to change passwords, I wasn't willing to invest that effort into it. The cost of good random passwords was too high. Today, if my password manager was hacked, it would suck going through all my accounts and changing all the passwords - it would take a lot of physical time, but there would be no long-term fallout and mental effort involved for me. I'm not attached to those passwords - I don't even know them.
Personally most non-trivial passwords of mine were generated by 'pass'.
Advantage over a password manager? - sometimes I have to document what the password is in offline technical notes or a password vault for the customer, and doing it this way lets me kill two birds with one stone.
#! /bin/bash
cat /dev/urandom | base64 --wrap ${1:-"10"} | head -n 1
Defaults to 10 character passwords, but you can put bigger numbers as the first argument. I don't think the `base64` command is on the Mac, so probably won't work there.tr -dc '[:print:]' < /dev/urandom | head -c 20
Disclaimer: I don't know much about this site and don't have any trust relationship with it. Have a read of the FAQ on the page and verify for yourself.
1. Make up a short nonsense word (so it's pronounceable).
2. Pick 3 numbers.
3. Make up another short nonsense word.
4. Concat them with hyphens, capitalising the first letter.
So let's go with...
Terp-745-mula
Mang-288-pung
The benefits:1. Heaps 'o entropy. Need more? Just make longer words.
2. Crucially: really easy to type on an iOS keyboard. You often start with caps on by default, and the dash-number-dash sequence in the middle only requires one use of the symbol shift key.
3. And, of course, fairly memorable.
I still use 1Password and the vast majority of my passwords are 16 characters of truly random nonsense, but for those times that you want a memorable password that you'll actually type quite a bit, this is gold.
---
And now I await the inevitable teardown of this method ... what did I miss? :-)
But yes, entropy is lost if you decide it has to be pronounceable. On the other hand pronounceable is in the eye of the beholder and a it allows me to memorize long sequences of nonsense (up to the point where it gets annoying to type for someone who consequently lock his computer every time.)
For everyone who are just starting to think of this here are some more tips:
- Do store passwords in a password manager! The only reason to memorize passwords is because you need the password for your password manager and your OS and certain other things available even if you aren't logged in to your password manager.
- Use real two factor auth whenever possible. Please be aware though that just adding "sms something" doesn't necessarily make things more secure. A common (AFAIK, and sadly) mistake seems to be to use SMS for both password reset and for the second factor. In this case whoever gets access to you phone for just a moment can reset your password and immediately get a "2-factor" login code as well. (Scare quotes because this isn't 2-factor since one only needs access to one thing, the phone, to get access in this case.)
- Some people will say that using SMS at all is hopeless, but from what I can see they can still make sense in a number of cases: not everyone has targetet attacks from three letter agencies (domestic or foreign) as part of their threat model. More people have - or should have - a point about losing access to login information as part of their threat model I guess.
I posted a Show HN last night for a side project I’ve built that can solve the email part of this: https://news.ycombinator.com/item?id=19296936
Long story short it became problematic pretty quickly and I ditched it. You need to also be able to reply as that email address too etc. It's been done a bunch a times I understand.
This is useful for detecting the origin of spam, however it’s trivial for a spammer or hacker to workaround (just strip the plus and anything after it before sending)
Got any links to these services?
It actually happened with the anti-spam services I‘ve used, twice.
Here's a few I made with `pwgen`, get it while it's hot:
aiPh9toh_ti{XeS(a=a9ohCheeV`o8pu8woh3Epu
ahth6AiT6xahaiw:ie1li`xeeF0ohf!ikeih4Joh
zah6cusohNei6feithain4aeH5uul5coh/nap0ea
uet7ed"ohhooquoosh3ooh8ZeeY+iepeg0eewena
UuNg'aes:i!Quohp0eiGh1ibieghe&o9eiSh7ac9
aexu0Vio3eitheiV=aiweo$ng@u3Seidoo-phoV1You can find lots of examples of throwaway passwords with associated accounts (and submit your own) at bugmenot.com
I'm sure there are so many culturally significant codes that get used as passwords all the time.
Or as I like to say when I see stupidity online or on TV: There are close to seven billion people in the world, dumb shit is bound to happen.
p.s. You're assuming that those first 10 characters are random and unique. But perhaps, not really. Maybe it's two 5 char strings of some other significance?
https://www.xkcd.com/936/ "Password Strength"
"Diceware" http://world.std.com/%7Ereinhold/diceware.html https://en.wikipedia.org/wiki/Diceware
This post brought to you by human rights gang.