Write your passwords down
blog.jgc.org
blog.jgc.org
I'd say about 50% of the people ended up with their current password on a post-it on their monitor or desk.
I'd based on the available data that could have just as much security, without all the user hassle, if we just require long passwords, no other requirement. Can you see how much easier it is to just say, your password has to be 16 characters or longer. Just think of a passphrase. For instance: IWa1kmydogonSaturdays Easy to remember, and I would argue, though would want to try to provide some evidence, that this would be just as, if not more secure than 8 characters with ridiculous requirements.
... then I bet lots of users will choose passwords like "passwordpasswordpassword".
... with all due apologies to PIL.
I particularly liked the suggestion (elsewhere) to set passwords to a random combination of three dictionary words. It's hard to remember 7Gw$kW_ws, but I bet I could come up with a meaning for "dog shower flange".
With a password the key is always entropy. You can use all the smarts in the world to avoid the pre-computation attacks on your password... but never forget that brute force is not limited to character by character attack :)
In fact, just one word with a couple of numbers has the same effect.
Don't forget though, you are trusting this password to a site. If they are hacked, what then? Your 2K years turns into minutes or hours.
So assume they've got something lame like SHA-1 hashes, even on commodity hardware you're talking about 100,000 hashes a second. Now you're at 2.5 years. Setup a simple cluster or buy some CPU cards, and you easily get into the three month range.
Never Never NEVER use SHA-1 or MD5 for hashing your passwords, those algorithms are designed to be fast.
Anyway, the technique is called "Diceware", and you can pretty easily calculate how much entropy you're getting with it. (and assuming your attacker doesn't know you're using diceware, you're in even better shape.
"antelope" has 14,100,000 results
"antelope walrus" has 118,000 results
"antelope walrus biscotti" has 8,100 results
"antelope walrus biscotti eisenhower" has 1,690 results
"antelope walrus biscotti eisenhower lambchop" has 8 results!
Bonus if you can find a word combo which produces a single page of interesting sites, not word spam. Of course now that this comment is on the web, make that 9 results for "antelope walrus biscotti eisenhower lambchop".An average vocabulary has something like a million words in it, if you word count derivations. If you can expand that by a factor of five with easily memorable things like 1337-speak transformations, you can get above 80 bits with only 4 entities.
I do a lot of pen testing, and one of the easiest ways to get access to important things is figure out a way to go into the IT department under some premise. Passwords galore, the rest is just memory :)
(this is, sadly, only a slight exaggeration)
Another reason to grumble over SOX.
Rather than writing the passwords down, use a decent tool like 1password (http://agilewebsolutions.com/onepassword) or Keepass (http://keepass.info/).
I have one super-strong password that I've memorized that encrypts my KeePass database, and then I use Keepass to generate and store random passwords for me.
It has a multifactor grid authentication, which along with a user defined password, makes it secure enough for me.
When I started using it, I changed most of my passwords to be 100 characters long. But many sites had a maximum 20 characters or equivalent rule.
- lame passwords for sites I don't care about (e.g., 'insecure')
- the same password for sites with semi-sensitive information (e.g., facebook)
- unique passwords for bank accounts, servers, etc.
So I try to strike a balance between difficulty in remembering & security.I'll use the 'insecure' password to drop a comment on an interesting discussion on a site I've just found - like, say HackerNews or Twitter, then two years later I'm still participating in the community there, and it _could_ have still had the password I used that time to comment on a ValleyWag story. All of a sudden I _do_ care a bit about any reputation I might have. I was fortunate this time not to have any sites I cared about still using the same old password Gawker leaked (mainly 'cause I'd learned that lesson when my twitterstream started spamming acai berry sites when PerlMonks exposed my low-grade password back then.)
I think Schenier's right - the world isn't a place where "remembering passwords" works any more. We need too many of them and we don't have enough control over how other people store them.
A password safe with a strong passphrase backed up by somethig like dropbox or zumodrive is probably a minimum sensible approach now. Some care is needed with the devices you access that password safe on, and awareness of how software like browsers or your OS caches and stores any passwords it sees you use. Even with a properly secured password safe, a fair number of my logins are probably hosed if I lose my laptop... Firefox, Chrome Safari, Mail.app, Twitter clients, IM clients, IRC programs, FTP programs - all of them store credentials for me, _mostly_ in Mac OS X's keychain, but not in a "reliable enough way" to be considered "secure" if the physical hardware is in someone else's possession.
Then, come login, I can just copy the password from the URL.
echo -n "A long sentence I can recall. site_name" | sha1sum
I use the sha1sum from that as my password.
site_name may be hackernews, slashdot, home, etc. I can break them in half (20 chars) or quarters (10 chars) if the site can't accept a 40 char password. Also I can add a period on the end if the site requires special chars. These are strong passwords and unique for each site. Works great on Windows Linux and Macs. All I need to do is recall my sentence (with proper punctuation).
Btw, do you ever worry that your command history might be accessed to discover your passwords?
No one but me uses it. So it's bare bones.
echo -n 'Secret sentence Sitename' | openssl sha1 -binary | openssl base64The very best GPU crackers do about 1 billion guesses a second. Good luck.
My current method for secure passwords on sites that have a max around 8 or 12 or so is to think of some song lyrics I know, pick n words, camel-case them, l33+-translate a couple letters, and add shift+numeral special characters to either side.
Edit: One other neat thing about this approach is that you can honestly say that you don't know what the password is (if you are ever asked). You know how to create it, but you have no idea what it is. That may matter in some situations.
I ended up writing a simple shell script using sha256sum and dicing it several ways, a GUI app seemed a bit clunky for me.
read -s p
hash=`echo -n $p | sha256sum | sed -e 's/-//' | sed -e 's/ //'`
echo '64: '$hash
echo '40: '${hash:0:40}
echo '20: '${hash:0:20}
echo '16: '${hash:0:16}
echo '12: '${hash:0:12}
echo '10: '${hash:0:10}
echo '08: '${hash:0:8}For those with openssl.
I love jgc but here he's making the same mistake most people make when they speak about security: assuming all readers have the same need for security and run the same risks. They don't. There is no point for my mom to adopt this system, it's way overkilled for her. (I think there's no point for me either).
One needs to explain to users two things: the first is that there is a big difference between being A target and being THE target. If you are just A target, picking one password for each website you subscribe to is more than enough. If you are THE target, then people will get to you, no matter how secure you think you are.
BTW Do you use the same password on your Gawker account elsewhere?
I checked the torrent and I guess I never made a Gawker account.
This for those 1.5m that were just A target; Nick Denton, OTH, was THE target and it was just matter of time for him to get pwned.
>BTW Do you use the same password on your Gawker account elsewhere?
I had to check the other day. I opened that account to leave one comment on lifehacker (that was never approved, actually) and then forgot about it. Turns out the password was safe enough but my mistake there was to use an email address I cared about.
Now I have a less important email address and a supergenpass for everything, except gmail/facebook/dropbox and the other things I care about, for which I have better passwords.
I'm guessing there's no real way to gauge this because I've never seen a study nor heard anyone else touting one and yet, complex password protection guidelines are always being recommended. Why?
There's always a risk, it's not expensive to defend against, so why not?
'thIs1smyp4ssw0rd19%2' isn't any less secure than another 20 character password that includes lower+upper case letters, numbers and special characters.
Obviously, if you do something like 'c0r1np4ssw0rd" then it may get to the stage where enough people do that for crackers to expect it (maybe it already is, but as long as you follow his third and fourth rules ("Use mixed-case, numbers and special characters" and "Use passwords of at least 12 characters") you really should be fine, and you'll have an easier time memorising them.
(I can remember multiple 20+ character passwords that would be very difficult to crack, and have no need to write them down.)
Sites like HN and Reddit I'm happy to use the same password (I'd be minorly annoyed, but realistically I wouldn't be that fussed if I lost control of either account, I can either recover it or even create a new one), but any site where someone finding my password could cause a problem has its own password, and I can remember them all.
Occasionally I forget which password goes with which site, but not often - actually I find it harder to remember which username/email goes with each site.
So very true. My password creation process is fairly memorable, and tends to meet the requirements of any site (password length, numbers, capitals etc). But user names - it's an email address, it's the name on your email address, they do accept spaces, they don't accept spaces, they only have 8 characters ... drives me mad !
It's hard to say in what order specifically they're going to try it, but generally speaking, they go from fewer bits to higher bits. thIs 1s my p4ssw0rd - that's not quite as many bits as you think it is. That's 4 permutations of dictionary words. That password probably hits the requirement of 80 bits, but it is less secure than other 20 character passwords. thIs1smyp4ssw0rd is going to be tried in its various permutations fairly early on in the cracking, and tacking on a few extra characters, while an order of magnitude increase in compute time, is not outside the realm of possibility.
The results will surprise you. The space of things you describe is far smaller relative to the available space than you realize.
You can indeed make this big enough to work, and it's easy to make it big enough that only a dedicated cracker could get through it, if that. My point isn't that you're wrong, but that you may be less right than you realize.
I could pick a password that is "coRInStaNdr3ws19@90" which is my first name, my first school, my year of birth, and a few capitals/numbers/special characters. If an attacker knows that's my type of password then it might make it easier for him, but 'corin' isn't in dictionaries (sure they might think to find out my name and add it as a dictionary word), and I doubt "st" and "andrews" would be. Realistically, unless I give away my rough password format, they won't be able to narrow it down and will be left with a password that's just as hard to crack as if it was completely random.
When you cut the possibility space down, you have cut the possibility space down. You can't fool entropy. The math is quite vicious that way.
You're encountering the "everybody can create an encryption scheme that they themselves can't crack" problem. You may not be able to think of how to abuse low-entropy passwords to crack something far longer than you "ought" to be able to, but that doesn't make it impossible, or even necessarily hard for an attacker.
Write that passphrase down and put it in a safety deposit box if you want people to be able to retrieve them after you die.
[1] http://ask.slashdot.org/comments.pl?sid=152097&cid=12762...
Copy this empty table: http://pastebin.com/tzbd7FCt Fill it with this random password generator: https://www.grc.com/passwords.htm
Be sure to use a fixed-width font.
Interesting guarantee for a random number generator to provide...
It's a browser extension for Chrome and for Firefox that seamlessly hashes the concatenation of your master password and the domain name of the site you're logging into. This produces a different password for each site, and requires you to remember only your master password.
The extensions were created by Blake Ross (big name in the firefox community), as well as Collin Jackson and Dan Boneh who are highly regarded security experts at Stanford.
Also, if you're interested, I've created a command line utility for Mac OS X that exposes the same functionality: https://github.com/ali01/pwdhash.py
A typical PwdHash password, with domain name google.com and master password "LetMeIn+123456?" looks like this:
6+LYoE/C0wP8dGPoO
Try it yourself at the pwdhash website.
password = base64(pbkdf2(secret, username@url))
Where PBKDF2 uses SHA-256 and 5000 iterations.You can get it here: https://chrome.google.com/webstore/detail/hegbhhpocfhlnjmemk...
Website version: http://sellme.ru/p2
Lets face it, none of this is every gonna keep you totally out of trouble. If you re so paranoid (aka my security professor at school), shut all your online accounts down.
Then you publish the fact itself and the algorithm in your blog(real name), which, besides, doesn't depend on a passphrase (which could turn your method in a sort of dual factor authenticator).
The paper could be photocopied and returned to your wallet and you'd never know.
Please, don't talk me about how many bits of entropy your passwords have. They aren't secure.
However, this being said, it is much more secure against untargeted attacks than the standard "i have an algorithms in my head" or "i use the same password" approach a lot of people use.
But on the other hand, your garage door works with a rolling keY too, and you're also SOL if you lose your opener (unless you, ironically, have a keypad).
You just called up, said you need the ID, and they read you the number over the phone...
Me: "Hi I'm XXX and I need the RSA key for COMPANY X."
Helpdesk: "Okay... It's on the board here somewhere... Found it... It's down to the last bar. Let me wait until it flips... Okay. Six bars... 643332."
Me: "Thanks a million."
The first few times I use a newly generated password, I have to look it up in a master file. It's weird how quickly semi-pronounceable nonsense + some symbols get stuck in your head though.
I'm having a very difficult time articulating just how horrible this idea is. Now if somebody compromises your password list, by either finding or stealing your wallet, they also get all of your personal and banking information as well!
There is a reason that the government advises people not to carry their Social Security cards in their wallet (http://ssa-custhelp.ssa.gov/app/answers/detail/a_id/446/~/ca...).
I use Wallet, a password manager/generator that's available for OS X and iOS, supports encryption, and syncs between devices automatically. I use a different random, strong password for all of my accounts, and it's easier to manage than keeping lists of passwords. Works for me.
Take for example, and this is just a sample not my own personal hash formula, the following mechanism:
key = username
1) r = rot2(key)
2) password = vowelreplace(r) [a4,e3,i1,o0,u_]
In this example, I apply a rotation of 2 letters to the input key, then replace the vowels in the result with numbers.
A sample use case might be for an amazon account.
Username: johnsmith
Password Key: johnsmith
Password Phase 1 (rot2): lqjpuokvj
Password Phase 2 (vowelreplace): lqjp_0kvj
We are quite capable of remembering simple formulas which we can use to generate our own passwords on demand. What's best is the formula exists in our heads, and can never be discovered laying around.
An example: I have an account with the bank Bancomer. In Spanish, "comer" means to eat, so I refer to it as "eßenbanque". (I know it's "essen"; nobody likely to find my list would recognize the ß, though; it would be mistaken for a B.) If my password were "l4rryb1rd" (it's not) I might render it as "oiseaulázaro", just enough of a reminder, while still misleading.
This scheme might not work so well in, say, Brussels, but here in Monolingüilandia I think it's reasonable, although I do wonder from time to time just how sound it really is.
Fun fact: the password based on Russian transliteration that looks NOTHING like any English word I've seen (imagine "cexuqakr3") trips the linux "too close to dictionary word!" warning while a less secure password that's based on two english words (imagine "bellykitten13") doesn't.
Having your passwords hacked or guessed is bad because it's a hassle, and it can lead to you losing time and money.
This method of password generation/storage is also a hassle, and definitely leads to losing time (which may translate to money).
I find it far easier to come up with a reasonably long and complex 'base' password, then tag an extra bit to the end depending on which site you're accessing. Since our memory is strongly context dependent, it's easy to remember the extra little bit for the site you're currently on.
There are many tools that let you do that on your mobile phone of choice, including my own http://memengo.com which has a benefit of also including the online backup feature in case you lose your phone.
Write parts of your password down in several places, collect some of them (say, 8 of 10) to reconstruct it (completely!) if you've forgotten it; let someone who finds your wallet with one part of it know nothing.
Not so sure how my loved ones would feel about my employer asking to go through my personal effects if I was in a coma.
And then there's the whole trouble of sites that require a username that you need to remember and that is usually restricted in ridiculous ways.
T#!$ p@$$w0rd w0uld &e re@lly #@rd t0 cr@ck.
T#!$p@$$w0rdw0uld&ere@lly#@rdt0cr@ck
The passwords for my important stuff look much like the above. Just write a sentence that's easy to remember, replace letters with the special characters they look like and blend it all together. Works a treat.
Example: - last 3 letters - a static symbol (let's use %) - @ if it's online / & if it's not - 3rd 1st 4th letter of topic in Capital-lower-Capital format - follow with a short string to increase length and stump bruteforces (lets use gold158)
So my password for hackernews would be: - ews - % - @ - ChK - gold158
ews%@ChKgold158
I'm no security expert, but that seems to be pretty secure and it will be different for each password. You won't ever be in trouble if you forget a password and it doesn't require you to carry around written passwords. If you scramble it a little better than I did in my example, it will look random and no one will try to "reverse engineer" your algorithm. (So when someone needs your password temporarily, you can tell them)