‘DiceKeys’ creates a master password for life with one roll
wired.com
wired.com
And of course a YubiKey or equivalent is the real answer. I'm trusting the developer there too, but I get a nice compact package that fits on my keyring, and a secret that never goes outside that package.
You don't have contact info in your profile, would you mind shooting me an email at mouserng-hnpublic@lucgommans.nl? As far as I could find, there has been no research into the randomness of those key-generating mouse movements, so I'm slowly (over months, probably will be years in the end) collecting data to finally do this. Collecting a trace for me shouldn't take more than two minutes of your time. (Anyone else who's interested is also welcome to mail me, by the way. The address will work for at least the next 7 days.)
[0] https://www.eff.org/deeplinks/2016/07/new-wordlists-random-p...
At some point, you're going to feed the entropy source into software. Having the app be part of your trusted computing base reduces the chance of a data-entry error that could leave users forever without their data.
For almost any real-world use case, memorizing the password and typing it in on a keyboard is pretty much a necessity. There are many kinds of inputs that don't allow another software like DiceKeys to enter the secret, so I'd still definitely rather stick with the simpler, human-readable option.
I'm probably an outlier, because I already have random dice, but "right leg squshr december 46 monday" seems secure enough to me: https://i.imgur.com/JGh4fik.jpg
Password crack time estimator sites are giving me times ranging from a few months to a few centuries to brute force it. Probably OK but I'd personally want something a bit better for a master password.
[1] 12 x 6^6 x 12 x 6^2 x 7 x 11! / 2. The first 5 factors come from the individual dice, the 11! covers order, and the divide by 2 comes from the two numeric d6 being interchangeable so order does not matter for them.
Under that assumption, yup. But naturally, if you were really going to do this, you wouldn't tell anyone which dice you used, or that you even used dice to generate the password. Ideally you'd probably use even more dice.
Of course, diceware is meant to use something most people can get their hands on easily; a day-of-week die, etc., isn't something you're going to find in a common game set.
Imagine that you do not trust electronics. Maybe once in the past, your PC's power supply blew up and fried every device in every USB port. Or maybe you were by the ocean once, and salt water got into your pocket and ruined every electronic device there. Or maybe you have read too much science fiction and are super afraid of terrorists setting of EMP bombs.
Either way, you want a key backup which is non-electronic in nature. What are you options then? Not many. You can generate a random QR code and and print it. Or you can write down list of 13 random words, bitcoin-style. But this is still paper, so it can get lost or easily destroyed. The box of dice, on the other hand, is much bigger (so it is harder to lose), and much stronger physically -- it does not care about water damage or mold.
Yes, this is not for everyone. Some people will want to backup using another electronic device, or maybe they do not care about backups at all. I'd personally use the "13 words" method if I had this problem. But I can easily imagine a person for whom the dicekeys would be the best secret backup solution.
Hopefully they'll release open-source scanner ASAP.
no, you don't. a) it's open source b) it runs locally
so, yes, you have to trust the software to some degree but at least you can audit it and it _should_ be relatively small amount of code. Also, you don't need to trust any remote site or the network because it doesn't use those and that's easy to test without looking at any code.
You can't audit most password managers and even if you could it would be a pain in the butt because they're so much more complicated.
> And of course a YubiKey or equivalent is the real answer.
as others have pointed out this is used to seed the FIDO2 key which makes it _better_ than yubikey because you can't really replace a lost yubikey.
KeePass is actually open-source now, and has been audited professionally. You are correct that a full password manager is more complicated than the dice; but the dice don't replace your password manager, so it's an addition to your attack surface, not a replacement.
And no, storing your secret outside the the tamper-resistant memory of a security token isn't better than registering a second (or third, or fourth, or however many makes you comfortable) backup token. HSMs and security tokens exist for good reason, and a cleartext backup loses that benefit.
I don't see anything wrong with marketing this as a cool toy, and as a tool to teach people how computer security works. I'm disturbed to see this marketed as if it solves a real problem, since that's at best a distraction from the steps (e.g., using a password manager and a hardware security token) that will help people practically.
In its favour, good, exogenous entropy mitigates part of post-hoc decryption attacks and wrecks the economics of passive bulk interception and surveillance. It means that threat actor needs to a) use direct attacks on user endpoints, b) sabotage algorithm implementations to truncate keys or c) bias the entropy source with loaded dice (because everybody knows...) or longshot d) use a TAO-like operation to add dice with duplicate facets from other cubes to dice kits in transit to reduce the total field size, which would be easily discoverable, but chalked up to a "printing error."
I use passwordless (GPG keys on an Yubikey) with a PIN code. The PIN can even be replaced by biometric soon. This is the way forward IMO. No more passwords at all, even master ones. If you turn on the tap-to-sign function on the yubikey you can also protect yourself from malware 'milking' your entire password database while the key is inserted. Of course I create the secrets on-key as is best practice.
Of course losing the token is an issue, but I have multiple and each password is encrypted against each of them.
I like this idea though. But I don't like that anyone who has a picture of the dice can generate the passwords. And I don't like leaving my password managers logged in all the time. It wouldn't work for my desired level of security, though I can imagine users who do leave their PW managers logged in, would be happy with it.
Then... how do you prove you're you? And not merely someone who has your physical body in their possession?
Edit: Obligatory "biometrics are usernames, not passwords."
I know there is always a risk of forgetting your master password but keeping it only in your brain gives you the most protection. I suspect law enforcement would have an easier time compelling you to give up your DiceKey object than forcing you to repeat your brain key. However I am not a lawyer and would be interested to hear more from those who know more about this kind of situation.
We have thought about designing a box that's intentionally very easy to open for people who want to encrypt their laptop when traveling into a jurisdiction that may want to steal IP or compromise their journalistic sources. We'd want the user to be able to slip their hand into their pocket and release the dice from the box before anyone knows to ask for their DiceKey.
Yes, at least in the US. There's good case law backing up the legal doctrine that the 5th amendment applies concerning anything known or memorized -- but that with a warrant, law enforcement can search a premises and seize items described by the warrant.
https://arstechnica.com/tech-policy/2020/02/man-who-refused-...
People should do this, and people should stop telling other people it's bad security to do this. And then people should stop using password managers.
The idea that the sticky note is bad is hilariously old school, and the result has been everyone putting their passwords in cloud-stored apps instead, which is 10,000% worse than a sticky note.
Remember: If it's on the Internet, your potential attacker is "every human on earth". If it's on a sticky note, your potential attacker is "everyone who can get access to the physical place you keep it". The former will always be an increasing number of billions of Internet users. The latter can be reduced to one or two if you store your sticky note somewhere very secure, like a safe or security deposit box.
Also, for added security... just lie on your sticky note. It doesn't have to be a high entropy lie to befuddle people.
Make up a sentence that makes sense to you, and remove all the spaces, use all lowercase and no special characters.
Forgettable: 5uP3r53kr17P455w00r[)!!11One
Memorable: ilikestartrekandhamandbeans
I used to have full-disk encryption on one of my machines using a password of the forgettable kind. But then the machine had an uptime of months until a power outage, and I realized that while I was fairly sure of the sentence I had no possibility of remembering all of the uppercase and lowercase and symbol and number substitutions. I lost quite a bit of data that day.
After that I began using a sentence that makes sense to me but which is not from a book or anything like that for the FDE on my desktop and external hard drives, and I use the pass phrase frequently. Simplicity and repetition is the key to remember your master password.
As for websites I use a password manager, and I sometimes generate passwords with my own diceware software https://github.com/ctsrc/Pgen but most often I am on my phone or on my laptop and then I use the password generator of the password manager that comes with those Apple devices.
I haven’t lost any more data since switching to managing my data encryption and my passwords this way.
This is why password managers are generally considered secure. They store only client side encrypted blobs and do not store or know your master password.
Like you, I have no concerns with storing your master password on paper in a locked drawer or something, but it’s unrealistic to securely store post its for every password you need as well as have them readily accessible.
For example, my 2FA tokens are backed up in physical storage. This means if I'm traveling and I lose my phone, I don't have access to them until I get back. But that's a lot safer than leaving them somewhere others can access them too.
Also, the website says you get about 192 bits of entropy. It's been a while since I did any combinatorics. It seems you should have 25! * ((6 * 4) ^ 25) possible dice rolls. 25! combinations of dice placement times (6 face up possibilities * 4 rotational possibilities) for 25 dice.
Python gives:
import math math.factorial(25) * (6 * 4)^25
496508538648719564809316402287439226010265627463254016000000
2^196
100433627766186892221372630771322662657637687111424552206336
We could have designed the software to try to recognize the top of the box, but the box for the steel version may look very different (or not be what you'd think of as a box at all.)
It's not like they're buying a $5 wrench or anything.
You could just as easily use a deck of playing cards or to construct a password and it would have exactly the same issues.
Yubikeys win the day again and again, I just more sites support them. The financial sites that would benefit most are still stuck on easily spoofed SMS authentication - if they even have that.
----------
https://github.com/dicekeys/dicekeys-webapp
We're just figuring out whether to use an MIT license or a license that forbids use in stalkerware applications and anti-citizen surveillance applications.
Some of our code is already public at https://github.com/dicekeys
(We welcome contributors)
But, most people are trusting software at some point. We're making sure our software is small and relatively simple so that you can audit it. That's one of the reasons why we don't take dependencies on Google's Tessearact OCR engine, or on frameworks like React. (The one big dependency we haven't removed is OpenCV.)
Before you transcribe, just rotate the box so that the first letter in the alphabet appears in the top left, than read in English order (left to right, then top to bottom).
The crypto library: cpp: https://github.com/dicekeys/seeded-crypto ts/js: https://github.com/dicekeys/seeded-crypto-js
If RNGs are that broken, the whole internet is broken- breaking a few passwords would be kind of secondary, wouldn't it? First up would be certain Bitcoin wallets, etc.
And now there a simple way for "a bug, virus, malware, keylogger, etc" to steal all of your secrets.
Not a parent, but this is one of the first things I thought of.