Speak Friend and Enter – Do people use movie passwords? (2018)
kobikobi.wordpress.com
kobikobi.wordpress.com
All the database leaks have shown that many people aren't nearly as clever as they think they are. I'm not sure if Passkeys are going to prove out as a good solution, so for the moment I am inclined to say your best bet is a good password manager and long, random passwords.
A decade or so ago, because I had to learn it for a school recital and know the poem backwards, I used Jabberwocky: Tbatstdgag1tw! - according to security.org’s password-strength-checker [1] that will take a computer 200,000,000 years to crack, presumably on average. I use a longer one today, and I skip words too, and some words I use 2 letters from - a similar string of characters to my current password is estimated at a trillion years.
At one point, I was using the first 2 lines of “Sea Fever” by Masefield, but that got too long to type - ImgdttsattlsatsaaIaiatsatstshb … If you’re interested, that’s 2 septillion years. I don’t need to be that secure :)
As an example, the chorus of the classic CCR song 'Have you ever seen the rain' (don't use this one) will give you a easy to remember 15 char password: Iwkhyestrcdoasd. And if you forget its easy to make a simple hint (something like 'Fogerty').
My advice, don't use the chorus - a 2nd or third verse you remember is better (and often longer). And google the lyrics before you make the password, just to check that you've been singing the right words all these years.
These types of things are very misleading. It is rare for a password to be bruteforced in general, it is unusual for the attacker to have the hashes of the actual site for an offline attack. Hopefully if the dev is competent there is rate limiting for an online attack. If the dev is competent they are hashing with argon2, pbkdf2, bcrypt etc tgat slows things down.
Anyways - 95% of password based attacks are using the same password in multiple places with one of the other sites getting hacked (someone's probably going to point out exceptions, and they do exist). Unless your password is absolutely terrible, the threat is not lack of password complexity but lack of password uniqueness.
Just to put it in perspective - 2FA is usually a six digit number, and that is considered secure since there are rate limits, and the user cannot reuse the key on multiple site. The security.org site says that can be cracked in 25 microseconds. There is obviously more to it then that since 2FA codes last more than 25 microseconds.
I do share those two (different) passwords around the machines I own, (ie: all login passwords are the same, and the iCloud password is shared of course) but I don’t see that as extending my risk at all. All of those machines are under my control for the login, and I know how well Apple secure the iCloud one.
Or much less time because it's already been leaked three times according to haveibeenpwned.com, so it'll already be in a bunch of rainbow tables.
This is why clever isn't enough: not because you can't design one that's resilient to brute force attacks but because password reuse is the #1 threat to the password-oriented security model and you can't come up with hundreds of sufficiently strong clever passwords.
The problem is not that i need a clever password, it's that I need 100 of them. Given that problem I either reuse my clever one everywhere, or have a formula based on it, and the domain.
In this age of scale, a password manager generating long random passwords is not "good to do", it's absolutely a requirement.
Now all you need is one long, clever, resilient password to access the password manager.
One day there will be an exploit for your password manager.
This is also why a platform should never confirm that a password is correct when 2FA is enabled, only confirm if both have been solved.
This is a popular trick in CTF exercises and it's pretty quick if you can make 1000 guesses per second. Takes a couple minutes until you're in.
However there is always risk, the question is - is it better than the alternative? For most reasonably designed password managers the answer is yes.
Heck for the average person, a sticky note on the monitor is probably better than the alternative.
Hence why I prefer "not great/not bad" passwords to sites that wouldn't have a significant impact on my privacy
"God" from Hackers is missing too.
In my youth, Joshua was a password I used a lot, and only dropped it because I felt it was, like, too obvious.
Another one I used, especially when numbers became mandatory was Turk182. But that reference is from a seriously obscure mid 80s movie (of the same name.) I'm guessing precisely nobody here has heard of it :)
Who flew? Who knew? Turk182
Ditto Pelham 123 from the 1970s .. although it did get a reboot in the 2000's
Bilby8x10^53 however . . .
They greybeards who came before me used names from the lore of LotR. I used house names from A Song of Ice and Fire (better known as the early 2000s tv series Game of Thrones, though the first book was released in the 90s). The youngsters after me used Pokémon names.
Humuhumunukunukuapuaa was eventually renamed because anytime you had to type it really sucked.
Names from Tolkien, movies, and tv got popular as workstations got deployed. Initially we thought the management had unclenched but learned that end users picked the names as these were machines deployed by individual research groups.
I was once tasked with reverse engineering a competitor's product, figured it might take a while but within minutes of running strings on one of the binaries it became clear one of the engineers must have been a major Game of Thrones fan. Talk about making your encryption passwords jump out :eek:
Random strings, folks, much safer to stick with random strings...
I actually wrote out that line in my journal with a calligraphy pen, copying the Elvish characters - one of my favorite fictional alphabets to this day.
Not anymore, seemingly.
https://tvtropes.org/pmwiki/pmwiki.php/Main/ThePasswordIsAlw...