The Worst Password Tips
xato.net
xato.net
facepalm. You can't use both? I do. This is horrible advice if taken on face value. To be fair, the author mentions things like KeePass. Use that. Make very long, random passwords.
>See, when it comes to a brute force attack, entropy makes no difference at all, because a brute force attack is a sequential attempt at every possible password, starting with the shortest first.
I think this is the biggest misconception regarding passwords. If we're using the phrase "brute force" literally, then yes. But if I were to write a cracker, I wouldn't be limited to that. The first thing it would do is grab the low hanging fruit. Examples:
1. Regarding the post, check all variations of a single digit repeating (say up to 100 times) in 1000 attempts. That's faster than I could check all variations of 2 character alphabetic passwords.
2. Check the same thing, but with all common keys on a keyboard layout (e.g. $$$$$$): < 10,000 attempts
3. Check common words in english dictionary: ~100,000 attempts
4. Check 10,000 most commonly used passwords: 10,000 attempts
Let me stop here and say that I can check ALL of the above in less time than it would take to check all variations of 3 characters using alpha, numeric, and common special characters. To put it another way, I could grab all that low hanging fruit in a billionth the time it would take to grab all the passwords in the "weak" format (8 random characters) given by the author.
What I have come up with above is my armchair ramblings. For some people, it is THEIR JOB to break your password. Please don't think you're going to create a good password by being clever. And please stop dismissing the issue by repeating the words "brute force"
There's only two good pieces of password advice:
Use long, randomly generated passwords (16+ characters). Don't use the same password on more than one site.
This can be accomplished with KeePass, LastPass, and there such utilities.
But the examples are oversimplified and might lead to worse password if a certain group of people come across the post.
P.S. My favourite tip for passwords is not to only have a password that is as random as you can memorize and never, ever, no matter what happens, write it down anywhere.
Of course you can!
I think you are taking many of my statements much too literally and misinterpreting the perspective of this article. Of course a long, completely random password made up of multiple character sets will always be the strongest password, but that really isn't the point of this article and it really isn't the most practical advice for most users.
There is a big difference between addressing where we need to be and moving away from where we actually are. Short passwords are not strong enough no matter how random they are. Therefore, I personally would rather see users out there focus on making longer passwords rather than focusing on random passwords. The typical user is much more likely to memorize a less random but longer password than trying to memorize an 8-character random password. I didn't mean to imply that randomness is bad, and I thought that most people got that from my article.
> Let me stop here and say that I can check ALL of the above in less time than it would take to check all variations of 3 characters using alpha, numeric, and common special characters.
These are all valid points and I could have gone into great detail on all the different ways our passwords could be cracked, but that just isn't the point of the article. I also didn't cover other things such as avoiding password reuse, regularly changing passwords, etc., but that doesn't make them any less valid and I cover them regularly through my other blog posts.
> And please stop dismissing the issue by repeating the words "brute force"
Not really sure what you mean by this or what issue you think I have dismissed by mentioning brute force. Brute force attacks are by n o means dismissing anything as they have become increasingly effective with ever-increasing computing power. Nevertheless, if an attacker has to assume that you will be using all character sets, the effort to crack your password grows exponentially with the length of your password.
>Not really sure what you mean by this or what issue you think I have dismissed by mentioning brute force.
Let me explain through analogy. I've often heard the story that a company will request a penetration tests and then restrict what can be done: "you can attack using method X, but not Y. A hacker wouldn't use Y."
That's a silly perspective, right? A black hat hacker is going to use any means available. When you say brute force, you seem to be specifying the method by which attackers will come at your password (and it's certainly not just you, many other people are repeating the meme). I think that's the wrong way to look at it.
Perhaps the confusion arises because you're making the assumption that someone will use some off the shelf, automated cracking software. That's reasonable. But automated != brute force. Again, if I were to write a cracker, it would first grab low hanging fruit. I've already given examples. Having a long password doesn't save you in that situation. That's why we think in terms of entropy.
>Nevertheless, if an attacker has to assume that you will be using all character sets, the effort to crack your password grows exponentially with the length of your password.
Agreed, but my point is they don't have to make that assumption. We don't get to decide what assumptions they start with.
In reality, most brute force attacks are attempted remotely where there is a bottleneck in terms of bandwidth and many services are rate limited. In such a case it would always make sense to try the most common passwords first.
The problem with letting people choose their own passwords is that most people just aren't that good at it and will choose stuff like p4ssw0rd1982, because people's minds are somewhat similar they will tend to converge on similar "good" passwords.
I ran an IMAP service for a time. We would constantly get bots attempting to brute force email accounts, we had fail2ban set to ban them after 5 attempts but they could get more guesses simply by having a lot of IP addresses.
When I looked at the sort of passwords they would try they didn't start with aaaa and move on from there, they would start with stuff that looked like it had been pulled from a common password list.
About once every 3 months we got a call from somebody who's email had been hacked. They all insisted that they were using strong passwords that nobody could have possibly guessed, however when I enforced a strong password policy on the server and offered a random password generator these problems went away.
OTOH I don't see why anyone would bother using a raw brute force attack against a password rather than just grabbing a dictionary of the most common passwords and exhausting those first.
In reality you are likely to run out of guesses before you hit the end of a common password list anyway.
Also use fail2ban to impose a lockout after a certain number of failures. The lockout does not have to be permanent, it just has to make a remote dictionary attack so time-consuming as to be infeasible (of course this does open up a DOS vector, depending on how you implement the lockout).
That's because they were. I'm sure that in the "underground" community of crackers there circulate lists of passwords that have been successfully cracked, because a) people tend to use the same passwords for everything, so if it worked for one account it will probably work for others, and b) the point you mande in your third paragraph.
These lists are continually updated and used as input to the "brute force" cracking tools.
* Simple Substitution < Add a whole word
* First Letters from a Phrase < Take the 3-4 words from a common phrase, add some punctuation
* Random Password Generators < longer password
* Personal Algorithms < longer passwords
A truly random eight character password containing upper and lowercase letters and digits is a keyspace of size 2x10^14. A four word passphrase containing random words selected from a 5000 word dictionary is a keyspace of size 6x10^14. They are comparable.
Right now, since almost everyone uses short passwords, length gives you amazing protection, because attacks are geared to find the common short password. But to the extent that the tech elite convinces the world to move to longer passphrases, that will quickly stop being true. It's no harder to program a brute force attack to try phrases of very common words, or very long, very low entropy phrases of other sorts (to be or not to be), than it is to try variations of dictionary words.
To the extent that we are giving people advice on security, it should be advice that is robust against the possibility of its own success.
This means that the most important password choice you can make is to have a completely different password on every site.
A software trojan, that can capture keystrokes, mouse movements, selected text, screenshots... Most certainly yes. :(
If you're storing them in lastpass, then they can grab them regardless.
If you're storing it in an encrypted partition, then they can grab them regardless.
Once somebody has access, it's game over.
There are still plenty of computers out there that are probably running vulnerable versions of Flash/Java etc. I imagine one of the biggest incentives to hack some random blog is to infest it with drive -by malware and compromise a bunch of machines if it has high traffic.
Also if you have a keylogger on a machine you can look for things that might be site admin passwords. So it wouldn't surprise me if there was a relatively symbiotic relationship.
Some prefer stuff like keepass that let's them store everything - i'm happier to rely on an algorithm.
Key point is to make using different passwords in different places really simple, so that people do it.
I agree that longer passwords are better, which is why I use very long phrases to generate my mnemonic passwords (typically 20-26 characters in length).
1. Use a different password for every application, especially every site.
2. Use a strong random password generator, typically software, to generate your passwords.
The first tip, which is not mentioned at all by the article, is particularly critical.
The password problem is here to stay...
Now for every password and email combo they have, they try to log onto a google account or bank account with the same information. Since you use the same password everywhere, they succeed. You're essentially now screwed and the attackers could do all kinds of devastating things.
Perhaps you say the scenario is unlikely - I'd say it happens more often then you would think. And this is the case where you're not even being individually targeted.
Overall - a little preventative action is hardly a burden and goes a long way to securing yourself online.
Your argument from incredulity won't add anything to the discussion.
If Randall has thrown in some punctuation and numbers then he's reducing the odds of that password being cracked. But as the example stood, it's advertising complacency against the most common method of modern password cracking.
It is absolutely the case that dictionary attacks are better than per-character brute force against the passwords Randal suggests, but he's not calculating entropy based on per-character brute force. He's calculating entropy based on per word brute force, and if the words are in fact chosen randomly that's the best you can do. Any dictionary attack against XKCD-style passwords are a brute-force attack in word-space.
"Throw[ing] in some punctuation" does comparatively little.
I cited a link in another fork of this comment where a pen tester comments about the words included in modern dictionary attacks.
You said:
> You're still thinking in terms of brute force attacks but actually dictionary attacks are more common as they rattle off the 'low hanging fruit' much quicker.
But the entropy calculations assume the attacker has the word-list. There is no low-hanging fruit, here. Strings generated by the algorithm are lowest-hanging, but they're all at the same height, and that's the number of bits calculated. The only attack is a brute force attack against word sequences.
It is obviously true that anything that's not going to be checked is going to be stronger than anything that is, but the correct assumption is that your key generation algorithm is public, and building something to attack Randall's algorithm plus punctuation is not significantly harder than building something to attack Randall's algorithm as specified (a few extra bits, to be sure, but adding another word or increasing the list you're drawing from will be more effective).
Incidentally, producing a literal dictionary is likely to be way slower than drawing words from the dictionary directly, since 1000 words will fit in memory and maybe even cache, while a trillion phrases is going to barely fit on disk.
> [C]ompletely random passwords, while harder to remember, will be more secure.
This is certainly the case, for a given password length. But the important point the comic is making is that we shouldn't be worried about conserving password length but about conserving memorability (and perhaps ease of typing), and for a given memorability the phrase is likely to be more secure.
The fact that passwords chosen in other ways are typically horribly vulnerable is MORE REASON TO USE THIS METHOD, not less!
The facts are this:
1. Dictionary attacks are generally used before brute force attacks
2. Random passwords can't be cracked via dictionary attacks
This is why I will always prefer random passwords. However I was never disputing that passphrases aren't secure either (in fact I actually said they are), just that I've seen people misinterprete that comic to mean that grouping a couple of obvious words together is more secure than random chars. My point was to illustrate how much more complicated password security is. And this argument where you've gone round in circles trying to argue your silly points actually emphasises that. (And I say 'silly' because half the time you're kicking off over comments that you've misunderstood / misinterpreted).
Added later:
Yes, dictionary attacks are more common. A dictionary attack is what converts this type of password from lg(27 ^ number of chars) bits, down to lg(wordlist size ^ number of words) bits. There's no way dictionary attacks can be used more effectively than that. Which is to say, the comic itself takes dictionary attacks into account and this kind of password (uniform distribution over words) cannot be cracked by a dictionary attack any easier than a "random" password (uniform distribution over strings) with the same amount of entropy, while being far, far more memorable.
A brute force attack takes an input of (characters OR words) and creates a (word OR passphrase) to test.
It doesn't help that you've made this mistake several times in this thread.
Imagine a 4 word diceware phrase.
One attacker has the diceware list of words. The attacker knows we have a 4 word phrase, and so starts kludging different 4 word combinations of the diceware phrase.
This is a bruteforce attack. It is not a dictionary attack.
Please supply any citation for the use of 'dictionary attack' where the attacker takes a list of words and creates pass phrases from those words.
I don't know why you think otherwise.
> you are picking guesses expected to be more likely.
That's not what defines a dictionary or brute force attack.
Anyway, wikipedia says:
"In cryptanalysis and computer security, a dictionary attack is a technique for defeating a cipher or authentication mechanism by trying to determine its decryption key or passphrase by trying likely possibilities, such as words in a dictionary."
What matters is not how the possibilities are stored/generated, but that you have a pool of possibilities that are substantially more likely, that you can guess first. But if you want to argue some technicality, fine. I don't care so much about the particular labels - what is clear is that, if someone generates their password correctly following the directions in the comic, updated appropriately, a dictionary attack of any form is not effective in reducing the search space below ((word list size)^(words in phrase)), which can be fairly secure.
Randal's entropy calculation clearly assumes a dictionary of about 2048 words, where the attacker has perfect knowledge of the dictionary at her disposal.
Randal's entropy calculation is correct, and the point of the cartoon is that 44 bits of entropy is much stronger than the passwords most people create using common password advice.
Personally, I think 44 bits is way too little entropy for a password, but I would be happy if my grandmother started using 44-bit passwords.
At the end of the day, the whole password model is broken, and Randall summed that part up succinctly.
Including less common words, and using 5 of them, makes things significantly better.
> grep '^[a-z]\+$' /usr/share/dict/words | wc -l
gives 62887 on my system, which is almost 16 bits per word, so 4 puts us at over 63 bits and 5 at over 79 bits, or roughly 15 quintillion and 1 septillion respectively. Assuming brute force over sequences of words from the same dictionary and of the correct length, at a billion tries each second, it'll take over 200 years to crack the former and over 31 million years to crack the latter.
This is why I would rather see emphasis placed on password length and irregularity than simply saying "memorable words can be secure", which is what most people will take away from that comic.
So I was never arguing against passphrases per se. Though I appreciate I want very clear on that. (Like I said before, hangover + phone surfing != best platform for a complex discussion. :-)
Just placing an emphasis on password length and irregularity leaves people still with the question of how they generate that long, irregular password. Asking them to do it in their head in any way is going to lead to much success by way of dictionary attacks.
I'm coming to the realization (giving you some credit) that your objection may be to a specific piece of the comic's particular presentation: "random" is often used to mean "arbitrary" and people might think they can do it in their head? Of course I agree that anything people do with their heads is almost certainly insecure - brains are piss-poor sources of entropy. Would your objection be fixed entirely if it called out explicitly that the words need to be picked mechanically (computer, dice, something) with a uniform distribution?
Anyway, the thing that I like about the comic is that it presents a specific means of choosing a password that is simultaneously secure and memorable, and the only misconception involved would be from misinterpretation of the comic (which, as noted above, does seem possible). Anything else someone comes up with on their own is likely to be less secure, less memorable, or both, so referring to the comic as promulgating a misconception bugs me.
Regarding the last, I don't think we were ever arguing about passphrases in general, but about a particular way of generating them... passphrase really just means "long password", more or less, and that doesn't provide a lot of guidance as to how to come up with one, and leaving people to their own devices is how we wind up with ~60% of passwords being horribly crackable.
But the crux of my point is that the comic doesn't necessarily teach good password habits. I do happen to work in infosec† and I've lost count of the number of pseudo-techies that rattle off that comic as evidence that obvious passwords can be secure without taking into account that they need to do more than just concatenating two words together.
You keep taking about ideal world scenarios (people picking passphrases and sites having sufficient max char limit on password fields to fit any conceivable passphrase), but people are idiots. So I'd sooner see idiots type a 10 char password from a pool of ~70 characters than two guessable words concatenated.
So my point was born out of frustration of having to advise and apply security policies for clients.
† I'm not just saying that to sound like an authority on the subject by the way. I know how some people "name drop" / lie about such things to prove a point :)
> I'm coming to the realization (giving you some credit) that your objection may be to a specific piece of the comic's particular presentation: "random" is often used to mean "arbitrary" and people might think they can do it in their head?
YES!!!!
You and I might understand the maths behind the comic, but many readers just see "words can be secure" and then just pick their dogs name and their favorite footballer. Randal's message gets lost because (and as with all of his comic) he assumes a certain level of intelligence to begin with.
> Regarding the last, I don't think we were ever arguing about passphrases in general, but about a particular way of generating them... passphrase really just means "long password", more or less, and that doesn't provide a lot of guidance as to how to come up with one, and leaving people to their own devices is how we wind up with ~60% of passwords being horribly crackable.
I think that's fair to say. Plus as I said before, I'm all in favor of passphrases. I just don't like regular words used as passwords. I know passphrases and passwords generally refer to the same thing, but I make the distinction because the former (passphrase) suggests multiple words, which agrees with your sentiments about how longer groups of common words can be secure and why I keep saying I'm fulling in favor of passphrases. Where as the latter (passwords) suggests something a little more basic (eg the dogfootball facepalm I described above). At least that's how I make the distinction between a password following Randal's advice that's secure, and one that's insecure.
No one ever suggests two-word pass-phrases are secure, and if they do you're right to cal those people idiots and make the stop doing it.
You keep mentioning xkcd; but that comic was not (even if other people are using it as an example) suggesting that people use just two words strung together. It specifically uses 4 words, and specifically gives the number in the list of words to chose from. It gives both of those numbers so the strength and weakness can be shown.
Actually you're thinking of the other guy. I deliberately tried to distance myself from that comic after it became clear that me initial point was completely misunderstood as an attack against Randal / that comic specifically. My point was about how people misinterpret that comic, and ironically everyone (including yourself) misinterpreted my post about that comic.
Quite frankly, I wish I never bothered to begin with.
> but that comic was not (even if other people are using it as an example) suggesting that people use just two words strung together. It specifically uses 4 words, and specifically gives the number in the list of words to chose from. It gives both of those numbers so the strength and weakness can be shown.
That was understood right from the start.
So my problem is that it gives the impression to be very secure whereas it's only secure under some conditions. (You have to pick words uniformly among the list of words.) Just like old password...
[1] As I've said in a few places, the actual dictionary size and number of words should be tweaked to make the security level appropriate for your needs, which will vary by application and grow over time.
* A relative’s name that isn’t particularly common
* The (partial) title of your favorite foreign language film or song
* A slang word from the area you grew up in
* The (partial) company name of one of your parents’ (former) employers
Those should be easy enough for you to remember, but will not show up in most dictionary lists. Alternative: you could use your pornstar name ;)
Or think of it this way, this algorithm can create a secure password from just 48 words chosen from a dictionary with just two entries! (let's call them "1" and "0" just to be contrary).
[1]http://arstechnica.com/security/2012/08/passwords-under-assa...
That has never, ever been my assertion. I keep saying a dictionary attack is a variation of a brute force attack (in that you're not looking at the hash itself), but adjusting the order in which you try words based on a priori guesses about what passwords are likely to be more common. My point has been that Randall's approach ASSUMES THIS KIND OF ATTACK. It, in fact, assumes a much more targeted one, where the dictionary the attacker has is completely accurate. IN THE FACE OF THAT, these passwords have the computed amounts of entropy.
(There is a separate discussion to be had of just how much entropy is necessary, but that's obviously going to increase as time goes by.)
I couldn't agree more that a maximum character limit (that's anywhere in the range anyone might conceivably type) is idiotic.
Internet arguments are fucking dumb. Half the time it's just miscommunication lol
Yes, the last bit was agreeing with you; the lead-in with "I couldn't agree more that..." was something of a clue.
Regarding the earlier pieces, you said in your original comment:
"That's another common misconception as that advice is only true for brute force attacks, which are usually only the last resort for password crackers. Dictionary attacks are pretty sophisticated these days so I really wouldn't gamble on a short list of common words being secure these days."
That is what I have been rebutting (in various forms, in various sub-threads), and it is incorrect. THE ENTROPY ESTIMATES IN THE COMIC ASSUME A MAXIMALLY 'SOPHISTICATED' DICTIONARY ATTACK, so "dictionary attacks are pretty sophisticated these days" is inane and misleading AT BEST. If you want to avoid miscommunication, communicate clearly, and either own what you say or say you were mistaken.
I really don't know who many fucking times I need to say this before the penny finally drops for you. Or maybe you just prefer acting like a dick online? Perhaps you're the troll?
Passwords are neither theoretically or practically reliable. They off-load security to the user, who is the weakest part of all the scheme obviously. Who is obviously uncapable of remembering by heart dozens of long passwords of random gibberish.
We should know better than use passwords.
Also, please let me know when you've convinced the major banks and web service providers to use public key cryptography instead of passwords.
For stupid services we can generate long random passwords, store them along. Not bothering the user with that.