Password Rules
portal.cs.oag.state.tx.us
portal.cs.oag.state.tx.us
I bought a house last month, and the biggest thorn in my side throughout all of the financial arrangements was security questions (I'm not even joking). Here's a Facebook status update I posted (I had already been complaining about security questions a bunch):
"Just got challenged with a security question, which was "Thank you for your loan application." Wtf, that is not a question. And I've never filled out any security questions for this website, so I have no idea what it's expecting me to enter.
"I swear, security questions are out to get me."
Of course, the same apps with security questions are probably the ones not hashing your actual password in the first place.
Think about last names, as well... there's huge variety in length, spelling, etc. -- it's poor customer service to force the customer to spell it out letter by letter -- so it's necessarily just displayed there on their screen.
The problem is that most sites won't let you set your own question. More about my idea on security questions: http://lucb1e.com/!65
One of the worst sites I saw demanded that I select my security question from a list. Sweet gosh, I have absolutely no idea which of your brain-addled security choices I selected.
"...but the account is being used for malicious purposes." - me
"Sorry, sir but until you tell me what you named your first dog I cannot stop it." - AOL
Do you mind if I quote you (with link) on my blog?
Google, too. I suggest you run through the recovery process yourself (on a dummy account, or your own) to see the kinds of questions asked. Questions like "when did you last access the account?" are easily answered; as is "name 5 regular contacts"; and so on. I could (but would not) perform the recovery process (and gain access to) acquaintances accounts, given how simple the questions are.
The key is just knowing "enough" in aggregate to pass their bar.
"...left curly brace. No, it's like the parenthesis, but squiggly. Are you using a regular keyboard? Hold shift and type the left square bracket. The square one. It's to the right of the P..."
Nightmare.
"No, the backslash. The one that leans backwards, no, I mean, to the left. Above the Enter key." Surprise, the backslash is not above the Enter key on Canadian bilingual keyboards.
What kind of company asks you to tell them your password by phone?
I don't remember for sure. I think it was a utility company.1Password gladly generates "pronounceable" passwords (e.g. "thax-lers-ponc-werv"). I usually think a bit about whether digits or symbols are required (some services and websites - Skype notably) don't like them.
A 20-char passphrase with spaces, dashes, or character-based (e.g. "S") word-boundary delimiter is often good enough to provide excellent (80+ bits) entropy.
Imagine I'm trying to crack into your site, and you lock any account after 5 failed logins in a row.
If I have access to (or can guess) a few thousand usernames, I can try the 4 most common passwords on all of those with no problems. I'll probably get some hits, no?
Or heck, I can try the 5 most common passwords, and not only will I have a few hits, I'll also have plenty of time to dig around without any attention from you, because you'll be struggling with a massive customer service nightmare, as thousands of your customers find themselves all locked out the same morning.
Edit: see my response to shard. No offense intended, and I hope none was taken :)
for more relevant info google "hunter2"
Austin#1 is a perfectly valid password according to those rules. zxcvbn says it'd take 2.508 seconds to crack that.
Any password cracking service would crack this in hours. IT people should understand the basics about security before they are allowed to set policy.
Not exactly, because you don't know where the special character is. If the allowed characters are k, the number of 8-character passwords would be k^8. With this rule, even assuming that only one special character is used the number becomes 7^k * (3 * 8) = 7^k * 24, so if k ~= 60 the entropy is reduced by roughly 1 bit.
Still, it is an incredibly stupid rule.
Though we know the first and last characters aren't special, so it's actually equivalent to reducing k to 18 for a single character, or 1.85 bits entropy lost by this rule and its interactions with the other rules.
... then the rule that the first and last characters can't be special reduces k from 65 to 62 for them, and the rule that no sets are allowed reduces k by 1 for every character after the first, and so on.
But really, I think the bigger concern is that all of these rules mean the password will end up on a post-it note stuck to the monitor.
Were you running a mod?
After a while I figured out "the trick" and could do them in my head and didn't need the program anymore. It was a fun little programming exercise, though.
I favor OpenID or something like it. Single strong form of authentication, delegate login authority from that to non-critical sites like Hacker News. OpenID has enough of a bad reputation now it's probably a non-starter. BrowserID has some promise: https://browserid.org/
The last time I changed a password for a service I set it to a phrase that I can easily remember but which no human or current machine will easily guess. I'd say that the only good rule is "Make it at least 9 characters" (which is at least long enough to disallow "password").
In my opinion it'd be better to just find a list of the top 10K passwords and disallow them.
One out of 50 people use one of the top 20 passwords. [0]
I'd bet that over half of passwords used are in the top ten thousand.
Not really. If X is the number of characters your password can be made up of, there are 8^X possible passwords that are 8 characters long, and 8^X-1 possible passwords that are less than 8 characters long. Even here, right on the border, you've only lost 1 bit of entropy (half banned, half allowed), and you win big the moment someone makes it even one character longer than the minimum who wouldn't have otherwise.
The number of passwords that are less than 8 characters long is X + X^2 + ... + X^7 which is significantly less than X^8 for large X.
So your point is even more valid.
Unfortunately, many sites enforce rules that preclude this password style (e.g., must contain a number).
The problem is when the usability/security trade-off doesn't match the situation.
How does that solve the problem of internet banking passwords? Banks are not "non-critical sites", so whatever form of authentication I use for my Reddit account is unlikely to be suitable for my bank. As a matter of fact, I don't trust LastPass with my banking passwords.
I use gmail + 2-step auth. You can configure it to be quite paranoid.
One of the reasons, why the British could crack the Enigma code, was that German officers introduced rules on how to use the system. For the Enigma machines they had to choose three out of five cylinders in different positions. The officers thought it would be more secure if they impose a rule "never use the same cylinder in the same position the next day".
Seriously, any decently sized organization should strongly recommend or mandate usage of such - they are also great when a transition needs to be made - known external credentials can be exported or passed during knowledge transfer and passwords reset.
I use Keepass to store passwords for the various things I use, and even though my hive is stored on a web server (uses SSL and requires a password, of course) for convenience, it has a well chosen, rotated password and a key file that I carry on a USB stick with my keys. I keep a backup of the key file in a safe physical location.
No two passwords are the same and none is less than 16 characters. One nice thing about Keepass is that you can also store URLs and other arbitrary information in the hive. Should anything ever happen to me, my wife will automatically receive instructions on how to locate and access the hive. (automatic email, dead man switch) Keepass also lets you set reminders so you can regularly change passwords.
To brute force your password, all somebody has to do is choose a starting word in Wikipedia and some number of consecutive words. This is log2(size of Wikipedia) + log2(entropy of your "5 or 6" distribution). This is less than 32 bits of entropy, or about a six character password in a 64 character alphabet, i.e. it's trivial to brute force this password if you have the hash.
It wouldn't be overwhelming to new users if they had examples of what a memorable passphrase is. You'd likely need to disallow specifically using the example passphrase but other than that, I'd be curious to see how well non-technical users respond to an interface asking them for a phrase.
Re: GP. Attackers would just switch to brute-forcing with common phrases. Song lyrics, expressions, etc. Then your passphrase rules will change to accommodate that, and be even more confusing. "The quick brown fox jumps over the lazy dog" and other long, memorable phrases, will be as insecure as "password123".
http://arstechnica.com/business/2012/03/passphrases-only-mar...
>> The "30 bits of security" means the chances of a single guess cracking a four-word passphrase would be one in 230. What's more, the two-word phrases cracked in the study provided just 220.8 (or 20,656/0.0113) bits of security. Another way of expressing the same finding is that a dictionary of slightly less than 21,000 phrases is enough to guess the login credentials that slightly more than 1 percent of people in the real world will use.
To be sure, that's a vast improvement over the security of normal passwords. Analyses of compromised passwords leaked onto the 'Net, including a corpus of 32 million plaintext codes dumped following the 2009 hack of online games provider RockYou, show that it's trivial to crack a sizable proportion of real-world codes. A dictionary of just two of the most common passwords—123456 and 12345 respectively—typically guess 1 percent of login credentials.
In theory, large alphabets and long passwords lead to increased password strength because they mean your password could have been many other things. In practice, the vast majority of those other things were never live possibilities, so the password is not that strong even if it is long or the symbol set is large.
For example, suppose you choose to base your password on your dog's name, Rover. This is one of maybe half a dozen likely choices for you, so is not a strong password. If you modify it for length and symbol set into Fetch4meRover!, this is still one of maybe a dozen things you would have chosen to do with the name, so is still not that strong in spite of the length and character set.
In general, you should not trust yourself to generate random information, and particularly passwords. Use a script to randomly generate a password -- a script with a known large number of live possibilities. This is the only way to ensure those possibilities -- the ones that make a password secure -- were ever actually live.
That is a trade-of because they will write it down and put it next to their monitor.
But then the bad guy has to physically get it and the password isn't going to be used anywhere else so you nuke the two biggest issues with passwords.
That sucks.
I imagine many sites implementing these policies (some banks etc) are hashing their passwords properly and sanitizing SQL though!
Has anyone ever analysed if password rules help at all? Aren't most compromises social-based or otherwise accidental? No one breaks in by slamming millions of login attempts at a server, do they?
So yes, sometimes. And no, I'm not certain why on earth I set that as my password...
I have never understood the number/uppercase requirement, if someone somehow put a key logger it won't matter or if some one is using brute force, it wont matter either.
Second, the mixed case alphanumeric definitely aids against brute force attacks, particularly in the case of an online attack (for an offline attack, there are probably hundreds of thousands of attempts per second so the only effective protection is a slow hashing function that limits attack speed)
The bonus is that I could still track how many quarters I worked for that place before leaving (lasted into the 6 quarter).
Any reason for that? Using pretty similar passwords with minor differences is how I manage to remember passwords for all those fifty different services I have to know password for...
See obligatory xkcd comic:
"Unfortunately time and again we have come to observe the inability of employees to follow simple rules during password creation. For example, despite our warnings, employees often create a password containing more than one consecutive non-numeral; other employees attempt to createa a password consisting only of numbers, only of letters, or an insecure mix of numbers and letters - e.g. 5:1 - with no special characters.
This is unacceptable.
Henceforth, new passwords must be one of the following five possibilities, as described below:
s$sVC!{IV{wG:|9 (Employees with last name beginning with A-F)
bE#40,$&T@V}266 (Employees with last name beginning with G-L)
U>~7nw*,55{][%H (Employees with last name beginning with M-R)
EL8$v{4#L8482 5 (Employees with last name beginning with S-X)
or
1^_4s"x&T3pB,%% (All other employees).
You may not use a password you have ever used previously. In two weeks, the new possibilities will be posted to the web site, and you must change your password immediately to one of the new possibilities.
You have brought this on yourselves, and if you begin to show an ability to use secure passwords, you may get to pick your own in the future. Until then, they will be assigned to you.
HR."
This is probably the root cause of bad passwords. In the case of Average Joe, he is now having to choose something memorable which is 8 characters long. 'PassworD'
Then when you go to reset your password they keep telling you that your password doesn't meet the requirements (the form allows you to type as much as you want) but doesn't tell you about the 8 character password rule. Then when you finally get one that works and you are logged in (12345678 is not a secure password, but apparently that is fine) you go to change your password and this time they will tell you that 8 characters are all that is allowed, but the web form is set to only accept 7 characters, so you have to use the Safari Inspector to change the form to accept 8 characters and submit.
And unfortunately I can't leave them because it is a loan and not just a checking account. Thing is, even I don't know my password anymore, so it is as secure as it can be :P
You may be able to refinance the loan through another bank, which would pay off this one and let you go with someone more reasonable.
Fictitious? Did you read the rules in the original post?
> 2. It must contain at least one letter, one number, and one special character.
> ...
> 5. Two of the same characters sitting next to each other are considered to be a “set.” No “sets” are allowed.
Yes. The grand parent post isn't talking about these rules per se, just a fictitious example of HR and bad password practices.