Correct Horse Battery Staple: Secure Password Generator
correcthorsebatterystaple.net
correcthorsebatterystaple.net
A local diceware generator is probably available in your package manager, e.g:
sudo apt install diceware
diceware -n 6
QuickenPrisonThermosDefilingBasicsVengeful cat /usr/share/dict/words | shuf | head -n 4For all of its faults, 5x six-sided dice looking up this wordlist (https://theworld.com/~reinhold/diceware.wordlist.asc) is something that can be accomplished by hand, without computer assistance.
Assuming you have trustworthy dice (they don't have to be perfectly balanced, just something you can trust to be random), then you can diceware your own password by hand.
https://www.eff.org/deeplinks/2016/07/new-wordlists-random-p...
I'm just a humble non-crytographic-programmer making practical suggestions with the most substantial security improvement for the least effort... Of course personally - I roll dice, dice that I whittled out of sticks, sticks from different trees that I collected from different parks, parks that I visited in a random order based on the results of a PRNG of my own secret design, a PRNG I built out of swarm crab based logic gates on a secret beach, seeded with a number collected from a geiger counter and small sample of u238, a geiger counter I constructed from photodiodes and aluminium foil, photodiodes I fabricated out of mud, rocks and fire. One day I hope to finish implementing my own general purpose computer and browser, then I will finally be able to use my passwords :)
For example, randomly selecting words from the Basic English Wordlist (https://simple.wikipedia.org/wiki/Wikipedia:Basic_English_co...), a list of 2626 words, could be a better methodology.
pwgen with the -s option will generate 'random' passwords, up to the randomness limit of whatever random source is provided by your kernel and system.
Audit the code? Maybe it's different tomorrow. Maybe it's different based on client fingerprint! Internet explorer users in retirement communities get the version with a known, fixed random number seed.
)=*vZqV
Grateful-Afternoon-Resistance-South-0
The second is much easier to remember, and common security measures need to be practical.Incidentally, I have two small shell functions to generate these. Tweaked slightly:
< /dev/urandom tr -dc '!-~' | head -c${1:-7}; echo
for i in `seq 5`; do
echo -n `grep --perl-regexp '^[a-z]{4,7}$' /usr/share/dict/words | shuf -n 1`
echo -n ' '
done* https://arstechnica.com/information-technology/2014/03/dicew...
They have 7,776 words in their list; that gives 77.5 bits.
Such as the Generate Password would be listed as:
> Correct Horce Battery Staple
> "Correct Horse-with-a-C Battery Staple"
"Horse-with-a-C" is a longer password, but could possibly be hit using an algorithm that expects "with-a-[letter]" to be generated as part of a password.
The randomized misspelling of a word-or-two was intended to break a dictionary attack.
If it is diceware, then the site's default 4 words hasn't been considered secure for a while. There is an Ars Technica article from 2014 that says 6 should be the minimum. I bet it is higher now.
Reminds me of the online bitcoin wallet public key QR code generator that just generated a code for some attacker’s wallet and got themselves some free coins.
"gen-password" generates random passwords, allowing your to specify length and character set.
"gen-passphrase" generates correct-horse-battery-staple-style passphrases.
Both are written in Perl, using /dev/urandom by default for randomness.
At a glance, the base dictionary is 2280 words; jargon is 8800; science is 575. So, definitely consider adding all the lists! That gives (check my math) ~13.5 bits entropy per word.
[1] https://bitbucket.org/jvdl/correcthorsebatterystaple/src/mas...
IMHO, it would be better if it would generate a list of passwords, so if the site is malicious, it wouldn't know which one you picked. It's weak, I know... But for this reason, I like this one: https://xkpasswd.net/s/
I also used dashes as a word separator and to count as a special character. Nearly everyone allows for - , but it is hit or miss for other special characters.
The fundamental problem with passwords is still the need for them.
Have a passphrase for each and let the password manager generate noise for everything else.
https://bitwarden.com/help/generator/#password-types see "Passphrase"
- you need a password for your password manager
- you also need a password for your actual desktop/phone, when the manager is inaccessible.
- you may have a work computer requiring a different password as well
Here are already 3, ideally different, passwords you need to remember.
Although after a couple of days of using a new password regularly, I can't help but have it memorized anyhow.
IMO the days of remembering multiple passwords are gone - either use a password manager, or thankfully the industry is moving to passkeys.