I Know What Your Password Was Last Summer
labs.lares.com
labs.lares.com
Like, I really don't get it. Why not just use a password manager. I always tell these people to just sign up for a password manager and they always resist and say no. I must be missing something obvious.
Edit: And just as I posted this comment, another bizarre personal strategy for creating passwords: https://news.ycombinator.com/item?id=39335853
Just use a password manager! Basically all password managers will generate a random string for a password when you add a new credential. You never even have to look at it or know what it is.
It's really no different, so I think there must be some human biased thinking at play. Except the password manager requires a central or synchronizing computer system, while the in-head key derivation approach requires no such thing.
The trade off is that pass mgnrs give more convenience, but have slightly more failure modes (not knowing the master password, not having access to the synchronization or master vault, not wanting to log into a pass mngr on a potentially compromised computer when you only need a single password you are willing to sacrifice) while the in-head approach has a single one: not remembering the derivation method.
ETA: both are sensitive to sites changing names or URLs. But password managers more so (requiring extra searching and clicks) while in a mental key derivation context, you would probably remember "oh, it's protonmail." without explicitly needing to distinguish "login.proton.me" from their old URL. But, that does make the key derivation approach slightly more susceptible to phishing. Not seeing the password autofill at least gives mental pause.
Public figures likely have their passwords individually scrutinized when their accounts are found out.
Plus, username needs to be stored as well sometimes.
Synchronizing is easy, put it in a network share or Dropbox/google drive/iCloud. If for some reason it’s inaccessible, keepass/dropbox will synchronize any local changes the next time you open the manager while you’re at home. This is a solved problem.
I think it would be like suggesting people give their life savings to their unreliable neighbor to hold on to. It might be safe, and might be secure, but at the end of the day they are being asked to bet everything on something they don’t find to be reliable.
In the end, perception is reality and I can’t say I entirely disagree with the perception. I use a password manager, but unless you are running the infrastructure and backups yourself, which a normal person isn’t going to do, you are at the mercy of “corporations” that we know to make mistakes, have data breaches, lose data, change their policies on a whim, break the law, and even cause people’s deaths, all while suffering few if any consequences.
I’d say the average person’s hesitancy toward using a password manager is probably pretty justified, even if it would be far more secure.
Maybe they don't want to be relying on a random third-party for all their passwords?
Rather than getting them to sign up for a password manager, what about getting them to install a password manager? I use https://www.passwordstore.org/ - it encrypts your passwords with GPG, and shares the storage via a Git repository for synchronisation between different machines.
What if I don't have access to the password manager at some point but I do need to log into some website? I.e. visiting friends house, forgot my phone at home but I need to log in my banking app to do a transfer? Or visiting a foreign country, someone steals my papers and my phone and I need to login to mail at a public cafe to let my family know I am well.
what I typically would do in both of those scenarios is a password reset. I would know my email password and do a password reset of everything else and get that in my email.
privilege escalate on yourself.
realistically, I’ve been at Apple Stores multiple times where I needed to login manually to my icloud account while my phone was being RMA’d. nothing to remind you there.
It’s because password managers are annoying at the worst possible times. The dread of “oh god… this device doesn’t support my password manager/im only going to log in once here, so I have to carefully type out random numbers and letters” is not fun.
Examples: office zoom meeting room tablet. Standalone VR headset. Smart TV. Trying to share an account for video streaming. (Solved by that being mostly impossible now) The wifi password every single person will ask you for when they’re at your home.
That sucks. People immediately imagine those scenarios when you bring it up to them.
every service on my TV pops up a big QR code for your second device (a phone) to access and log in with
iphones prompt you to share the password when your iphone using friend tries to connect to a wifi network you are on
Regarding VR, hm knowing an Apple Vision Pro will be connected to my icloud account makes me know I wont have to do that stuff. Other standalone headsets I wonder how or if they solve that problem. My Playstation VR headset dual renders on screen so the qr code solution is already there.
So yes, I was too dismissive. Given the nature of "security", I think it's impossible to have a silver bullet of secure + easy.
Another factor is inconvenience. On the road, most passwords are out of reach for me now. In a way I prefer it that way, I prefer to not be glued to my phone. As a compromise, there are a few passwords in a note taking app on my phone ;)
Also, here's why people don't want to use a password manager:
https://arstechnica.com/information-technology/2023/02/lastp...
Let's not pretend like password managers are a silver bullet.
I will sync via icloud or another encrypted backup at my discretion
But everything convenient did something dumb
I don't have "real" social media accounts to begin with, so my life won't be ruined even if someone cracked all my passwords. Mostly it's just accounts for various online shops I've used during the years. I really don't care if someone hacks those. And access to my bank is pretty much worthless if you don't have my phone and the pin code sheet too. Well I don't have big money in bank anyway, so the crime doesn't pay well in any case.
Is this satire?
Some fancy password manager service can be attacked by anyone with a network connection or the budget to buy the company. And there's an actual incentive to attack the password service because it doesn't just have parent's passwords, it has many passwords.
I think the only downside to the sheet of paper is that people with physical access are probably more likely to be specifically interested in you, and therefore willing to put in the effort to figure it out. But they'd probably figure it out anyway if they're that interested (install a keylogger or camera or something).
For sure, but hopefully folks are using solutions where the provider can't decrypt their data, much less attackers.
Have you ever had to hope that your lined paper wasn't going to fuck you over?
(keepass2/keepass xc are more user-friendly and free, strongbox is another good front-end for keepass files as well.)
Exactly, they'll be a memory in 10 years. https://fidoalliance.org/passkeys/
Simple, I don’t trust a cloud service to keep the data secure, and I don’t trust myself to self host and keep the data safe (and not get corrupted) while simultaneously getting that data on all devices and synced.
The flaw of password managers is that you don’t know the passwords you’re using for your sites. That is, if the data was lost, you’d have to do an account recovery, which for some sites is fine, for others it can be a nightmare though.
Alongside this, it is a hard problem to have to simultaneously get all of these copied-pasted passwords on each device without inherently putting them on the Internet (albeit with a password in front of them). Given a threat model of password managers being inherently valuable targets, data going in and out of them is inherently vulnerable for when an exploit is inevitably found.
I’m not saying any of these problems makes mental hash algorithms or rotating passwords better, but password managers do have inherent flaws that make them still an unideal tool.
Also, I find it ironic in the modern day that a simple sticky note next to your computer is probably one of the better solutions to password management, if people invading your physical space isn’t part of your threat model (which is usually the case).
It's typically a 5-minute process, which I know because services regularly force password resets quite often.
> …I don’t trust a cloud service to keep the data secure.
Fair enough, there are definitely shady SaaS vendors. My password manager is a SaaS with a long history (2006), which has no access to my account passwords or Secret Keys and could not reset or recover them for me if I asked. I'm personally satisfied with that.
Have you considered the benefits? For example, I know I currently have 1,161 account logins on various sites/services, 278 of which have "fantastic" passwords, and 144 which have "fair" passwords that I should really go back and update (surely from my pre-password-manager days). I know there are 5 accounts that now support 2FA, and many more which now support passkeys. I know when I've last used each so I can easily close old accounts, which I gradually do.
That kind of awareness/security hygiene enablement would be tough (if not impossible) to replicate manually.
You can easily remember 4 to 6 random words. You really will be surprised how quickly it is to memorize and type after a day or two. Mixing them up with what separator (if any) that you use, and if you number/special character substitute that adds dozens of possible permutations on a single password. And just using 4-letter words (over 100,000 in the English language) leads to a 100 quintillion possible passwords without any separator or character substitutions.
The next requirement should be no arbitrary changes to passwords. End users should be able to pick a strong 16 character password (based on uniqueness and the other password strength tools they recommend in the article) and only change it if they forgot it or a breach of their account is suspected.
Much safer than anything like Xak1k99u??.1 which no one can remember efficiently
I think the answer is distributed password managers, myself.
When you run large IT systems, external auditors come into your systems and say :
1) no password rotation = bad
2) no password format enforcement = bad
Though it’s absurd to force people to have a password between 6 and 8 chars for example, because it limits the amount of possibilities.
For humans. Service/admin accounts should be rotating constantly.
The NSA password reset questionnaire is hilariously a great life memory quiz.
Almost everyone needs to reset some passwords daily even though we had the phone number keypads with special characters around. How to remember passwords was a routine conversation because certain systems had admin passwords to remember or passwords that would change at odd intervals or single account multiple user passwords.
It came down to “how long after a password reset do you actually need to change the password? Does it check for past passwords?” There were passwords written down in not so secret places because the admin would not always be at work.
Eventually we had to adopt token authorization which is a mess to implement also. I loved the security meetings only to discuss how screwed we were once they started enforcing policies.
Is it nog a bit more likely that there was some duplication in the hashes?
Or that this password is used by one prolific account creator? Or that it is the default password after signup for some blue service?
Depending on the type of hashes... Absolutely not.
1. The section beginning with "If you are interested in the respective hashcat masks for the passwords cracked above," is most obviously AI-generated as it makes no sense. Quote:
> <Passw0rd1><Passw0rd2> > > Mask: ?1?1?1?1?1?1?1?1?1?1?1?1?1?1?1?1?1?1 > > Explanation: This mask is for a pattern that starts and ends with angle brackets. Inside, it follows a pattern of "Passw0rd" followed by a digit, repeated twice. However, Hashcat doesn't directly support angle brackets in its mask. An option would be to handle these characters separately or use a custom charset (?1) to represent them.
Angle brackets aren't special characters in masks: https://hashcat.net/wiki/doku.php?id=mask_attack
If angle brackets were special characters in masks and had to be represented by ?1 as a workaround, this mask is unrelated to the explanation, since it would match passwords consisting only of angle brackets.
"handle these characters separately" isn't a thing.
The mask doesn't have anything to do with matching "Passw0rd".
Several other masks from the page do not match their accompanying passwords.
Most of them are just showing the uppercase letters, lowercase letters and digits in the password. E.g. "We matched Hello123World with a mask matching 1 uppercase letter, 4 lowercase letters, 3 digits, 1 uppercase letter, and 4 lowercase letters." This doesn't explain why anyone should use that mask instead of, say, 1 uppercase letter, 4 lowercase letters, 2 digits, 1 uppercase letter, and 5 lowercase letters. This is obviously not the mask they used, but an AI working backwards from the password.
2. The password "Cloudy-Envelope-Rainbow-Dinosaur" is 32 characters long, including the hyphens, not 29 as the article says. The password "Sunset$Guitar$Puzzle$Journey" consists of 28 characters, including the dollar signs, not 27 as the article says.
3. The "Conclusion" section smells strongly of AI. Windows was only mentioned in passing, yet the conclusion says the whole article is about Windows. MFA wasn't mentioned at all until this point. Defence in depth wasn't mentioned.
I firmly believe the safest option is a local password manager with randomized passwords that you maintain local backups of.
You also get mostly out of the key management business, because you can say “if you get locked out, call the help desk”, vs personal usage where backup keys / account recovery requires a per-service recovery flow.
It's something like 50trillion sets of looks-random strings. That's quite a lot, but if the list could be narrowed very significantly to get some likely results by selecting locations in:
1) cities where a company is physically located
2) large capital & global cities
3) significant landmarks
I see sysadmins using the tool all the time as a temporary password generator.
I even keep my vaultwarden on a private network and have an always on wireguard vpn on all my family's devices.
It is nice, because it has the option to keep http open on the subdomain for doing let's encrypt stuff, but the actually SSL site will be internal only.
tr -cd "[:alnum:]" < /dev/urandom | fold -w 20 | sed 10q
Then I use an encrypted text file via Emacs to store my passwords
strings -10 /dev/urandom | head
It's less efficient but easier to type, and also helps with websites that requires non-alphanumeric symbols.I'm joking. But what if I weren't? Especially if you're going to announce this on the internet, it sounds far more effective to add 1 character to the end of your passphrase instead, since each exponentiates any brute force effort, and isn't defeatable by a simple pattern.
(Or announce on the internet that you're doing something far more complex, like running bcrypt on all your passphrases to generate your passwords. That would make an attacker's life significantly more difficult than base64.)
(Or always lie on the internet about how you generate your passwords. I hope that's what you're already actually doing.)