The logic behind three random words
ncsc.gov.uk
ncsc.gov.uk
"Creepy wet uncle"
and I giggled. I kept reading and once in a while there was something funny. After a while I realized that 3 random words can make me laugh, but no 3 random words made me cry.
Before I thought that laughter and crying are equal but opposite emotions, but they are not. Crying is much deeper and requires more emotional attachment. To make someone laugh all you need is 3 random words.
Let's just say the phrases on some of those cards were quite choice. Thankfully everyone had a sense of humor about it and it wasn't a big deal.
I dunno, there's probably a fair number of people who might cry at something like "Unused baby shoes" (obviously cribbing off the apocryphal Hemingway story.)
Turns out that when you generate over a million random letter sequences some of them are rather fruity words. In fact my original code was being referred to as "the random f*k generator" lol
https://www.wordnik.com/words/jew
edited (I got the whole M Jackson backwards, removed it)
Attributed to Ernest Hemingway though there is some doubt, supposedly written in response to a challenge to write a very short story:
"For sale: baby shoes, never worn""For sale: baby shoes, just hatched."
but that's back to laugh.
In comedy we say "Hah!"
In art we say "Ah!"
All three are expressions of the experience of making novel connections or seeing things from a new perspective.
Diceware is the older brother of this method:
This article contains reasonable advice, but I am not sure that is advice that anyone is interested in. Let me explain.
Most of my tech savvy friends/family use password managers (either digital or paper), two factor authentication, and sometimes hardware authentication devices for important accounts.
In contrast, most of my non-tech savvy friends/family do not care about password entropy or really anything to do with security. If the complexity requirements cause them to forget a memorized password, then they reset using their email.
Edit: Actually people forgetting their passwords because of complexity requirements might be useful, since it forces people not using a password manager to login by clicking a link from their email (which is better than a weak password) In this light, maybe companies should start to enforce even more crazy requirements at least 4 numbers, 4 symbols, 8 characters
I'll try: people are lousy at random picking. Their choices are highly likely to come from the most common 1000 words, and very very likely to come from the most common 4000 words. If this is true, it gets you an entropy of 30 to 36 bits.
BUT
Just for curiosity I checked out NIST's current guidance on passwords; they actually allow 6-digit passwords (PINs) [with about 20 bits of entropy], as long as there is server-side rate limiting of authentication attempts [edited to add:] and are uniformly chosen by the server. They recognize that this does not mitigate offline cracking attempts. Since even choosing a random "top 100" word would meet the same entropy bar, perhaps my initial reaction is an over-reaction. [https://pages.nist.gov/800-63-3/sp800-63b.html#appA]
We had 8char, special, number, rolling 90 days, etc. Awful. I had looked at 3 random words as advice and same conclusion, even at 10,000 most common words, it was beyond trivial for offline cracking.
10,000 most common words ^ 3 and 100,000,000 guesses / sec is a few hours to crack.
That’s the same complexity as 6x random keyboard characters. Not even sort of good. Our last pen test was rife with offline cracking.
I ended by teaching passphrases and recommending at least 4 words or whatever tricks they like and will remember. In four years since, not a single forgotten password request.
It still irks me how many places have 1. short password length limits and 2. stupid character class requirements. I use long as heck pass phrases everywhere I can't use a password manager but a shocking number of businesses are still like "max length 12 use 1 capital 1 number 1 symbol" :/
[0] https://www.ncsc.gov.uk/files/Cyber-Essentials-Requirements-... (page 8)
"crystal lizard rekindle" became "crystal LIZARD r3k1ndl3" etc.
Put the "!" at the front or in the middle. That way if you accidentally type or paste the password into bash or zsh it won't end up in your history.
That's because "!foo" or "bar!foo" are parsed as requests to substitute the most recent prior command that starts with "foo" in place of "!foo". Assuming you don't have such a command in your history this fails with an error about event not found. No command is generated, and so there is no attempt to run a command, and so nothing goes into history.
"foo!" on the other hand is parsed as an attempt to run the command "foo!". Command attempts do go into history.
But you realize any serious offline cracking is going to get both of those right?
Common word in lowercase - no problem
Common word in uppercase - no problem
Common word with 1337 replacement - no problem.
All you had to do to make this significantly more secure… was add a fourth word and not do the things that humans think are clever and machines don’t really care about.
Although I concede that the stupid requirements that websites have make simple passphrases more difficult than needed.
If you stick to one language and add a fourth word, you're adding 10+ bits of entropy (depending on the size of the word list you're choosing randomly from).
Hun$@ngF0rM3g-K@rp3_W19m This was a base password I used for about two or three years, altering the W19m ending to be a familiar measurement value for me, like walking 19 meters. It's actually lyrics from a song "Hun sang for meg", from Norwegian band Karpe Diem (song name is "Byduer i dur"). It falls into the problem of replacing letters with alike symbols, but that provides the complexity requirement, while also having enough length to be secure even without doing letter replacements.
My worst passwords are often for the things I should really keep most secure because they have the dumbest restrictions that cripple complexity.
8-16 characters long .. okay, there goes ALL the normal password bases I use, most my passwords are 24-58 characters long.
Only - _ ! . for special characters .. what the actual f**? Why? WHY? This is for my online medical account, WHY!?!?
Edit: 3*14 = 42, not 52...
Whilst I appreciate the recent shift to advising passphrases (and password managers, but that's a different topic) for normal users, the I've noticed that received wisdom tends to be that the words need to be unrelated, i.e. don't use a quote from a book (although I notice that the NCSC's own guidance[1] does not state this).
However, surely this would be an acceptable workaround for those who would struggle to remember (or, as you say, conjure up) an assortment of random, sufficiently-complex words? Password diversity would be enhanced if the text-based authentication ecosystem included traditional passwords, random passphrases AND semantically-meaningful sentences, more so than with only the first two?
Of course, quotations have their own strength problems (i.e., in a language like English any sentence will contain a lot of 1–3-letter words), and perhaps ‘it was the best of times it was the worst of times’ would just become the new ‘123456’, but perhaps the ecosystem-wide strengthening effect could mitigate those?
[0] https://www.ncsc.gov.uk/blog-post/the-logic-behind-three-ran...
[1] https://www.ncsc.gov.uk/collection/top-tips-for-staying-secu...
I don't think this is a problem with an easy solution. The low hanging fruit, enforced password rules, has been tried, further strengthening requires alternative solutions, such as 2FA, hardware keys, one-time pads, etc.
Just in case: correct, horse, staple, battery are far more frequent, and acquired earlier in life, and thus more likely to be part of a passphrase than e.g. rime, bagnio, pungently, cruse.
Ex: "All we have to fear is fear itself" Ex: "It was the best of times. It was the worst of times."
and then reduce it to only the first letters of each word:
Ex: Awhtfifi Ex: IwtbotIwtwot
The phrase is the memorable part, and then you simply have to encode it into a seemingly random string of letters that are unlikely to be dictionaried. Salt it with numbers and other characters and I think that makes for a halfway decent password.
Of course, I just use a password manager and all actual passwords are 20bit strings.
Also GP’s reducing does is make it harder for humans to remember and easier for machines to crack.
My thought process is that a hacker is likely to run a dictionary attack before resorting to a brute-force method. Therefore (all else being equal) a password consisting of nonrelated characters is safer than a string of actual words. That said, I also understand that more bits in a password makes for a stronger password, so any “reduced” phrase needs to be sufficiently long.
Any flaw in my approach is more out of a naive understanding of how cryptography and hackers may actually work.
Also, 20 bits (less than 3 bytes) is very short.
Also, a generator for the above [2].
[1] https://xkcd.com/936/ [2] https://www.correcthorsebatterystaple.net/
It seems a lot of people took the xkcd at face value.
[0] https://nakedsecurity.sophos.com/2012/08/13/correcthorsebatt...
Or some people stopped caring
If a system requires an account/password, and people find ways to bypass or weaken account security, perhaps you shouldn't be using accounts.
In days of yore, "cypherpunk/cypherpunk" or "cypherpunks/cypherpunks" was a common convention. Those are found 140 and 38 times respectively in haveibeenpwned.
Considering many systems went out of their way to prevent / disable such accounts, and the convention fell out of practice, that's notable.
int random() {
return 4; // randomly chosen by roll of a fair dice
}In a similar vein, React intentionally calls user-implemented functions which are meant to be pure twice in a row (even though that's technically unnecessary), just to ensure the programmer actually makes the function pure (so the application behaves reproducably in the future).
Edit: I'd be interested to see what others do!
I use diceware with few words in the low tier. Diceware with more words in the high tier. The password manager autogens the middle tier. Most people only need to really know a couple.
The issue being that the users who have to remember their passwords are often not the same people who decide whether or not to authorise the use of password managers.
http://canonical.org/~kragen/sw/netbook-misc-devel/bitwords.... has several different ways of generating strings of random words from strong randomness, as well as other forms of random passwords. It uses the frequencies from the British National Corpus http://canonical.org/~kragen/sw/wordlist. The word lists I've found most effective have 2048 or 4096 words, thus 11-12 bits of entropy per word; much larger lists of words include a lot of strange words that are much harder to memorize. So, person acid hidden, cases truck merge, KNIT SOOT CEIL, worn profession products, claw gerry teeth, or TIDY ANY HUG, but not fitzwilliam preside maxine, relieve scottish seminar, or tunis orange formerly, which use a 32768-entry wordlist.
However, three 12-bit words is only 36 bits of entropy. If an unsalted password hash database containing 2000 users' passwords gets stolen, every 34 million hash operations will yield one of those passwords. If a salted password hash gets stolen, every 34 billion hash operations will yield one, but the attacker can choose which one.
To non-computer people this probably sounds like a lot, but john on one core of this quad-core laptop can try 8500 md5crypt passwords per second or 480 bcrypt passwords per second with 32 iterations. So one password cracked per 34 million hash operations, assuming md5crypt, is one user account cracked every 17 minutes, and one password cracked per 34 billion hash operations is an average of 12 days to crack your target password.
Unless the attacker has more than a US$300 used laptop to attack with, that is. If they're using a 19" rack full of equipment, possibly equpiment that doesn't actually belong to them, they could quite easily have 256 times as much hashpower, so they can crack your password in 65 minutes. Or 19 hours if you were using bcrypt or something better like scrypt, configured for that level of resistance.
By contrast, if you use four random 12-bit words, they'll need 130 years with my laptop to crack your account if it's using md5crypt, 6 months if they're using a rack full of equipment, or 9 years if they're using the rack full of equipment but the passwords were hashed with 32-round bcrypt.
With a 72-bit-entropy password like "thank reason massive derived reasonably go", "pick sat adams orcs arabs being", or "ALL JURY SAUL BILK ADD RULE CUB", you should be reasonably safe even with a poorly chosen password hashing algorithm and a more seriously funded attacker.
If the password hash database is not stolen, and the attacker is limited to an online attack, three words might be reasonable, but four words is safer.
A key point that people often miss here is that you really need to use real randomness to generate the passwords. Don't use "random" passwords from your mind, because, as any mentalist knows, those are enormously less random than you think they are. Use actual physical dice, as with Diceware, or /dev/urandom.
Users hate IT security. IT security like all professions has become blame shifting not about security and made the problem worse.
Password complexity rules don't matter in practice. This keeps users the most happy and is close enough.
OT:If you are a hacker and care about TLA, passphrases seem the best but you need more than 3 words and you need something random in the mix. This is if they have your encrypted hard disk for instance or wallet.