http://arstechnica.com/security/2013/10/how-the-bible-and-yo...
But the point is being missed - two months? "I taught my wife in two months the passphrase"? Completely moronic.
(You could still make the point that two months is two long for any phrase, I'm sure, but without knowing how much more complicated it is than your example, and without knowing how different people manage learning things, that's hard to say.)
But let's pretend we're talking about complication for a moment (a much more interesting conversation to all of us anyway), and then let's realize that this very sentence probably would take about a minute to memorize, and would be completely uncrackable.
You're forgetting password cracking 101 - it gets a lot harder, even if the word/phrase only gets a little longer, or a little different. Sly dogs instead of lazy dogs, a hand in the bush is worth two in the bird, sally smells sea shores by the she shell, every fine boy does good; what do you want from me? You'd never crack any of those, and we both know it. Why? You'd never try them. You just wouldn't. Show me the algorithm that'd come up with, "No champions, play like excuses!" Only 32 characters, should be trivial. Right?
Let's imagine the phrase you were saying needs to be remembered is simply "password", whereas a phrase good enough to not be cracked actually needs to be 400 characters long and include punctuation and numbers. In that scenario, you would be thinking "should take 10 seconds to memorise", whereas realistically it takes much longer.
That shows that the difficulty of phrase is of course relevant to how long it might take to learn, and the fact that other people have been arguing with you over how difficult the phrase needs to be shows that it is debatable.
So maybe you're right that your example phrase is fine, but if his wife learned a much more complicated phrase then it could well take longer to remember.
The difficulty of the phrase is not relevant to how long it might take to learn, because of how cryptography works. That is, a 60 character phrase is much harder to crack than a 58 character phrase. So, the difference between "password" and "this is the password I'm going to use from now until the end of eternity" is cryptographically large, but trivial, memorization wise. So while the difficulty of the phrase to crack just jumped into "not gonna happen" land, the difficulty of the memorization of the phrase moved from instantaneous to 5-10 minutes.
If his wife learned a much more cryptographically complicated phrase it still would not have taken her longer to remember, making the specific phrase completely irrelevant. Two months is laughable, "taught it to my gf" is doubly laughable, and "gf (basically a wife)" is off the laughable charts.
And the phrase isn't in english, but in russian translit.
Kinda like this: PustVsegdaBudetSolnze$PustVsegdaBuduYa
Good luck cracking it.
You don't know it's alphabetic, you don't know it's an actual English phrase, you don't know how long it is, you don't basically know jack shit to be able to effectively use a dictionary attack against a password like that. You don't know it's a passphrase, basically.
The fact that there's google results for that phrase means it's a useless passphrase.
http://www.banjohangout.org/archive/251990/14
"You always find something in the very last place you look."
Bamn.
Now show me the actual algorithm that generated the passphrase without knowing the cleartext beforehand.
If the attackers knows that your password is constructed in this fashion, then it is trivial to track the password, as we've restricted the search space to a multiple of the number of common English words. The entropy argument only makes sense if the human readable strings are just as likely to be chosen as passwords as other random strings, which is not at all the case.
For example, my /usr/share/dict/american-english contains just shy of 100,000 words. A random word chosen from that set has 16.6 bits of entropy, and four randomly chosen words has over 66 bits of entropy. If anything, XKCD's comic is understating the entropy involved.
This is why some websites assign passwords to users and do not allow users to pick their own custom passwords. The only safe passwords are those generated by machines.
This does not mean that picking words to form a pass-phrase is less secure than picking letters to form a password.
Does less entropy not mean less secure? Or am I just reasoning about the entropy all wrong?
Then all bets are off, but they don't, so we're sorted.
Mind you, my /usr/share/dict has ~ 100,000 words in it. 100,000 5 is around the same order of magnitude as 62 12, which is the number of 12 character passwords of upper and lower letters + digits.
This is probably quite close to what a brute force passphrase cracking software would do as well, and he's not even adding bits for common alterations, such as capitalisation of first letter(s), spaces between words, common substitutions, etc. So the 44 bits estimate is for a software matching exactly this pattern, using exactly this common English dictionary.
Also, I suspect throwing in a single word from another language would greatly increase overall strength, especially if it's an uncommon word.
2048^4 = 17592186044416
2^44 = 17592186044416[0] The original http://www.princeton.edu/~wbialek/rome/refs/shannon_51.pdf
[1] and some evidence that it's still correct http://en.wikipedia.org/wiki/Hutter_Prize
Diceware uses a set of 7776 words. You select words from the list using 5 dice. 5 words, picked using 5 rolls of the set of 5 dice, gives you about 64 bits of entropy.
> A five-word Diceware passphrase has an entropy of at least 64.6 bits; six words have 77.5 bits, seven words 90.4 bits, eight words 103 bits
Because our attacker knows that we've used Diceware, and knows what diceware wordlist we used, and knows that we've used a 5 word passphrase, there are 7776^5 phrases to try. That's 28,430,288,029,929,701,376.
http://world.std.com/~reinhold/dicewarefaq.html
I'd be interested if you think Diceware is broken.
Crackers are using phrases from literature and the bible. Trawling the rest of the internet is not far behind.