Fortunately the readme on the target page appears to show the tool defaulting to passwords of considerably higher security than demonstrated in the comic which ought to provide reasonable security under a broader set of attack models.
Fortunately the readme on the target page appears to show the tool defaulting to passwords of considerably higher security than demonstrated in the comic which ought to provide reasonable security under a broader set of attack models.
The big thing (in my opinion) that the comic gets wrong, and that all implementations of the password spec follow, is that if an attacker has reason to assume you might be using this style of password, then each word sort of becomes a single "character," albeit from a much larger list of possible characters. But if you introduce some random numbers or special characters into the words, it's still easy to remember and type, but becomes much more difficult to crack.
If you ask users to do so themselves they tend to do so in extremely predictable ways that add l1ttle entropy!
If you do it automatically and in a way that has high entropy the result is a lot less memorable.
Probably just adding an additional word adds more entropy at less memorability cost.
I find it just as easy to remember correcthor_sebatTerystaple, and it effectively changes the attack from guessing which four words were used from a well known dictionary.
It might help to understand what people have done here: There have been absolutely gigantic plaintext password leaks. Armed with plaintext passwords and collections of very good 'dictionaries' (might not actually be dictionaries) attackers design rules to turn the dictionary into as many passwords as possible without duplication.
I think the "ah-ha" moment for me was realising that I needed neither to be able to remember nor to type my passwords.
Once that happens, passwords like 5Ze2vz7AdDjWbXXq start to look great rather than awful :)
Right, but the whole point is that the (hopefully) one-time pain of doing this is worth it in the long run.
Why you think that is "wrong"? It's the whole idea behind passphrases to consider each word as a symbol, and it's also what the xkcd entropy calculation is based on.
> (Plausible attack on a weak remote web service. Yes, cracking a stolen hash is faster, but it's not what the average user should worry about.)
And he's right (if you don't trust the website to hash the password securely, then you should assume your password is stored in plain text anyway)
E.g. I've seen people get burned using the comics advice for "brainwallets", which is equivalent to having a published unsalted hash.
It's okay to have a confined security model, so long as you understand that's what you're doing. But users usually lack any real ability to gauge how likely password hashes are to leak just due to lack of information on how the sites operate. I think a better justification of the comic's original security level is that it's sufficient for protecting things where a compromise is only a nuisance, as is usually the case for 'random website'. But that isn't true for all password choices people make.
I think I'll be fine.
Also, I use real dice.
Let me know if I calculated that wrong. The calculation was: (6^5)^6 / 1000000 / 2 / 60 / 60 / 24 / 365
The constants:
6 - sides on a D6
5 - dice per phrase
6 - phrases
1000000 - checked passwords per second (super optimistic, unrealistic hardware, outside even government reach)
2 - half way through a hypothetical dictionary attack
60 - seconds per minute
60 - minutes per hour
24 - hours per day
365 - days per year