I've had users use parts of lesser known poems or stories in some foreign language, because who would expect that, right? Turns out that's not what's relevant to a good password but rather whether it is in any available corpus.
If your passphrase consists of something likely to be in wikipedia you are guaranteed to get owned in minutes.
Now that I think of it, a non pirated OEM windows key would have made for a great password. ;)
Yeah, I had that one committed to memory in highschool.
It's like saying "My password is the first 10 characters of a really popular book about wizards" and expecting no one to figure it out.
Then consider that this is Hacker News, and how many of those 5,000 have both the skills and motivation to exploit the information you've provided.
Never give out "hints" about your password. Not its contents, not its exact length, the physical location in which you store a copy, nothing.
_Taps side of head with index finger_
Unless there's something fundamentally wrong with the password, a public length of n is almost as secure as a secret length of n, and significantly more secure than a secret length of n-1
Never get into the specifics of a password, but explaining the basic structure should be a tiny impact and well within your margin of safety, or you didn't make a good enough password to start with.
Good luck (Tell me how and where I can make this stronger)
Make it 8193 characters long, change it every 27 days at 11:04am, but most importantly: use it on exactly 0 websites.
Good luck
So whether providing your length is a tangible security leak or not is essentially a function of the size of your character pool, because if your password is short enough for n-1 to contain a significant percentage of possible combinations then it's probably already short enough to brute force anyway.
A good way to look at it is to measure the password in bits of randomness. At most, revealing length can shave off one bit. For any reasonable character set it shaves off a small fraction of a bit. And one bit does not make the difference between good or borderline or bad.
If you worry about any speedup in password cracking that is less than an order of magnitude, your password was too close to failing to start with. Make your password 5% longer, which will make it at least 20x slower to crack, and then you won't have to care if "20x" gets reduced to "15x".
You may say "It's not harmless to give up 25%. What if I give up 25% several times? That could make even a good password become insecure." but there's a limit to how much speedup someone can get from knowing the structure of your password. And the best way to evaluate the strength of a password is to assume that all the structure is public. So I can say that my typical passwords, being 20 mixed-case letters and numbers, all have a security of 2^119. It's possible that an attacker that uses the wrong algorithm would have to guess even more, but I'm not just worried about a clumsy attacker, I'm also worried about a moderately-high-quality attacker. It's a bad idea to depend on that extra .1 bit I could get with this character set, or that extra .4 bits I could get with a smaller character set. Just assume the length is known.
And that's fine, we can have different opinions on that part.
But "probably already short enough to brute force" is definitely not right. That percentage depends entirely on character set, not the length of your password. If your password is just numbers, then n-1 always has 10% as many combinations, whether your password is 5 characters long or 200. If you meant "probably already weak enough to brute force" that's not true either. Lots of passwords with mixed case and numbers and symbols are very short and pretty weak. Lots of passwords with only letters are very long and quite strong because they're made-up phrases. You can't guess the strength of a password just by knowing the percentage of [length n-1 combos] / [length n combos].
But we don't seem to be resolving anything so I'll just hope you have a good week.
Please point to the part of my statement which reflects this idea.
This seems to say that a small character pool, aka "n-1 containing a significant percentage of possible combinations", implies that your password is "probably already short enough to brute force".
So small character pool means that "probably" the password is short/weak.
I'm saying that a small character pool does not imply that a password is "probably" short/weak.
And to be very clear: Using the size of the character pool to say it's "probably" weak is a form of "reliably predict[ing] if n is sufficient".
What am I misreading?
> So small character pool means that "probably" the password is short/weak.
I really don't know how you came to that conclusion. I never claimed any dependence between the character pool length and password length. They're obviously completely separate properties.
Right?
That percentage comes entirely from the character pool.
So character pool -> percentage -> probably short enough to brute force.
What am I reading wrong? The only assumption I made is "compared to a password with length n", because what else would you be comparing length "n-1" to. Otherwise it's a direct quote.
I'm shocked by this subthread!
I probably used the same key to setup over 1000 PC's when I worked there.
https://www.godaddy.com/domainsearch/find?checkAvail=1&tmske...
https://domains.google.com/m/registrar/search?searchTerm=fck...
I guess people on here are 30-ish, so it happened 15 years ago in the 00s. This hints strongly towards WinXP, which has a few famous leaked Serials.
https://www.urbandictionary.com/define.php?term=fckgw-rhqq2-...
I've seen the above but for some reason mine was more prevalent in my region. Common enough that even my friends could recite it.
bound by the power of cerealz
Ensure you specifically permit loading jQuery from cloudflare.com, and check network traffic using a test password first.
Once a friend shared with me one of those services, he got surprised when I raised my concern about compromising his password, he took a second to check the developer tools to see if there was any request including his password, there wasn't, so he called me crazy (it's well known that malicious sites behave differently on certain conditions, one is having the developer tools opened).
Anyway, I suppose that this blind trust is what makes phishing attacks so effective.
I had always wondered if they do, and I've known it's possible, but this is the first time I've heard any accounts of it. Would you have more info on this?
There are many ways to detect it's open (eg. https://github.com/sindresorhus/devtools-detect) and it's also possible to mess with it without knowing it's open. A method that's wildly used is firing the debugger break command many times a second, along with other stuff that makes using the tools nearly impossible (slows the browser down to a halt)
It seems like a huge oversight to not detect ad blockers and let the user know that their password is being transmitted in plaintext if that's true...
turns out 204 other people can too! (though apparently not in all caps)
never used it as a password but i can see why one would
I had to replace the card a few times, but only the first number stuck.
When I was a kid I didn't understand why Sim City 4 Deluxe played after install but didn't play when I stuck disk 2 back in and clicked the game. It was my favorite game for a number of years and it wasn't until at least 2 or 3 years in I realized it wanted me to stick disk 1 in for the copyright protection and that disk 2 just worked during install for convenience reasons. I had been uninstalling the game every night before I went to bed (preserving saves!) and reinstalling it every day after school. One day I couldn't find the case with the key (probably got thrown away) and I thought I was going to have to buy it again but when I went to the computer I was able to get it first guess.
Been 15 years now. I suppose I'm never going to forget that key.
You aren't fooling no one, might as well just say it.