Passphrases You Can Memorize That Even the NSA Can’t Guess
firstlook.org
firstlook.org
All these nice pass-phrases do is protect you against people that get big user dumps of hashes like we saw with the recent Slack security breach.
The NSA doesn't need to guess your passphrase. The Chinese equivalent doesn't need to either. They'll just literally watch you type it in. Or use existing vulnerabilities to capture the traffic at your border router. And if you're REALLY a person of interest, they'll just use their CIA equivalent to capture you and torture the information out of you.
% ./passphrase.pl 10
coppice-topped
belly-naked
bastard locust tree
diamond bort
middle-aged
self-mapped
air level
field gun
machine rifle
chock stone
% ./passphrase.pl 10
self-knowing
soul-killing
Magna charta
fly-killing
spring chicken
blotting book
finger-cone
gauge glass
Fort union
assistant examiner
% ./passphrase.pl 10
soya-bean oil
foxtail pine
island-dotted
four-way cock
side-bar rule
benzoyl hydride
straight-fibered
steel town
stone bramble
rag-boilingThat said, "straight-fibered four-way cock" is my new favorite passphrase.
With the web2a list slightly tweaked, I get many memorable passwords, e.g., "power-weaver-sand-screw-1081" or "cloud-ring-tea-fighting-1107". OTOH web2a is shorter (~76000 entries), giving 2 bits less entropy vs. using the filtered web2 list. Taking password readability into account, the higher rate of "keepers" with web2a probably evens out the difference.
BTW the web2a word list is here (https://svnweb.freebsd.org/base/head/share/dict) in case anyone doesn't have access to it.
password password password password
and most of the online entropy checkers[1] says it's really safe to use such .. is this true?The only way to guarantee the entropy of a passphrase is to generate it from a source of high quality randomness (e.g. a CSPRNG or by actually rolling dice, hence the name "Diceware"). Diceware-style passphrases simply balance this requirement with usability by optimizing for things humans are typically good at memorizing (strings of words).
Relevant Dilbert:
My thinking was that "Correct Horse Battery Staple" had more entropy than: "go go go go go go go go go go go go go"
.. which, apparently, is not
A password from the space of "things users think up while staring at a dialog box for 5 seconds" has a much different probability distribution than "random strings". There are common passwords, and that's an exploitable pattern, but recognizing those patterns is difficult. All the typical entropy checker is going to tell you is how strong the password would be if it were a random string.
Any pattern is, in principle, exploitable. If I use ten digits of pi as a password, a programmed entropy checker isn't going to know that's easier to guess than ten random digits unless it has been told that, and including all possible exploitable patterns would require rather better software than can currently be written.
So don't trust the results too much.
What you really want to know with passwords is, "Is there outside information that would make this easy to guess?" Does it conform to some external, independent pattern, or are all the patterns in it things you made up after seeing the password itself?
That is why I am a big advocate of random generation as the only safe way to make passwords. Knowing the strength of a password is the same thing as knowing the size of the class of live probabilities from which it's drawn, and to do that you have to characterize the method used for generating it.
If your sample space is "all words in the english language, capitalized and uncapitalized", then the second one has more entropy than the first one. But if your sample space is "all characters or runs of characters that appear in the passphrase", the second one has a whole lot less entropy.
Well assuming random guessing with 95% vocabulary coverage its about 50,000 words. A passphrase checker that doesn't start from there but rather works from the ascii tokens is likely not very helpful for checking the strength of a passphrase.
> ... should be 8 characters or longer, which forces you to use multiple words or extra symbols. > ... should have upper case, lower case, symbols, and numbers; or at least three of those four groups. > ... should not be a common word and should not be a common phrase. > ... should not contain a date, a name, or other things that can be associated with you. > ... should be created randomly or semi-randomly. > ... should not be a suggestion when you type in the first few characters into Google.
As for your cited tester, you seem to have ignored every single piece of advice on the page and it seems it doesn't test for it in an automated way. I'd say, in this case, the problem is a bug in the tester rather than the truth of that being "safe".
If you had followed the guidelines, yes, it'd likely be reasonably safe.
From the article: Not too bad for a passphrase like “bolt vat frisky fob land hazy rigid,” which is entirely possible for most people to memorize. Compare that to “d07;oj7MgLz’%v,” a random password that contains slightly less entropy than the seven-word Diceware passphrase but is significantly more difficult to memorize.
At one trillion guesses per second — per Edward Snowden’s January 2013 warning — it would take an average of 27 million years to guess this passphrase.
I think this is one of the greatest unspoken benefits of Diceware-style passphrases!
https://raw.githubusercontent.com/dbasch/clj-brainwallet/mas...
Here's a browser implementation. I wouldn't use it (do you trust your browser's prng? Do you trust my code?) but it's fun to see the passphrases it generates, and how easy it is to create a story to remember them.
http://diegobasch.com/passgen/
Same thing applied to generating bitcoin brainwallets. Once again, don't use this. It was just a fun experiment to see if I could keep money in my brain.
You can think of a great passwords scheme for yourself, and then find yourself in a pool of shit where hotmail asks you to have maximum 12 characters in a password, facebook requires you use a number, but it can be up to 40 characters, amazon wants you to use a special character like an @ or a # and but has a max length of 15 so on and so on.
Passwords. Suck. Use a password manager that autogenerates and autostores it like lastpass.
First, write down 36 words. Roll two dice, take six times the number on the first minus the number on the second plus one. That is the position in the list of the first word in the sentence.
Next, write a new list of 36 words, but only include words that make sense given what is already there. Roll again as before and pick as before. Reusing words between lists is fine, but don't include the same word in the same list multiple times.
Rinse and repeat until you have the desired amount of entropy. Each die thrown adds log_2 6 bits.
Edit, just tried this, 36 is a lot of words to come up with. Much easier to write down 6 at the cost of making it twice as long. Unless you have access to lists of nouns, verbs, etc.
Bored now, but came up with "Countries can slowly sit at my feet", 24 bits of entropy (some lists had 36 words others had 6. It's very low, but, if you did that 2 or 3 times, you'd be getting somewhere). Couldn't be easier to remember.
Here's my attempt at memorable password generation: http://rmmh.github.io/abbrase/
By 'easy-to-remember', I mean for 99% of the world's English speaking population (i.e., for a widely used application).
I'm trying to estimate the entropy of random, easy-to-remember words. I'm not trying to generate a list (which would vary by region and country).
It could be useful for a master password, though - such as the one that secures my password list. Isn't just remembering a line from a song a little easier? Then you get a password recovery mechanism too, as long as you remember the song, or at least the artist!
[0] http://www.reddit.com/r/Bitcoin/comments/1ptuf3/brain_wallet...
As for the hundreds of passwords in your list, I'm convinced a password manager with a master password/3rd party auth/dongle is the way to go. Otherwise it's impossible to have unique passwords for all sites, rotate them, and remember them. Of course the risk is of losing the dongle.
Interesting observation, the usual objection is due to the reduced Kolmogorov complexity which is difficult to quantify. Let's look at a modified diceware scheme of the form:
Article adjective noun adverb verb adjective noun
A (non-random) example might be: The young boy really likes video games.
I'm not going to go through the diceware word list and classify each word, but assuming it is (or could be made) 50% nouns, 25% adjectives, 14% verbs, 11% adverbs and four articles you'd get roughly: 2 bits + 11 bits + 12 bits + 10 bits + 10 bits + 11 bits + 12 bits = 68 bits, which is the equivalent to a 5.2 word normal diceware password. Most of that reduction comes from the article.
Here's a random example made with a diceware generator:
an straw scrim ne adorn drab sybil
I'm not sure that's any easier to memorize.
While I think the set of adverbs would be much smaller (and obviously the set of articles will be very small) you could easily approach the same entropy as the Diceware method with a longer phrase. So long as there are 7 words in the phrase with 7776 possibilities each, you're equivalent. The rest is mnemonic glue.
Since I think nouns are going to be the easiest set, shooting for something even more noun heavy could help.
Edit: though since you're now syntactically more likely to be used in the wild, you'd probably want to search to make sure the phrase wasn't used in some other source. Problem there is the search leaks your password...
If we go back to the original 'song verse' idea, the space of all valid/written phrases is much smaller than the space of all possible word combinations. It's vulnerable to dictionary attacks based on commonly chosen phrases and frequency of phrase use in language/culture.
Wikipedia only has 2.4 billion words, out of an estimated billion English words [1]. Perhaps we could add project Gutenberg with it's 50,000 works, and all the song lyrics we could find on the internet. We may hit 5 billion words. Let's estimate we also get 5 billion 6-word phrases out of that set. We've lost a ton of entropy.
Ultimately, we suck at passwords. Machine capability will exceed what we can reliably, efficiently memorize.
[1] http://www.languagemonitor.com/number-of-words/number-of-wor...
If you wanted an absolute ranking of password strength, you'd first want to construct a universal brute force dictionary of passwords. Clearly the password 'password' is going to be near the beginning of the list and a password consisting of 48 randomly picked characters from [a-zA-Z0-9!@#$%^&*()] is likely to be somewhere out beyond the number of particles in the universe. But where exactly is "When you ain't got nothing, you got nothing to lose" going to appear? The first 10 million? billion? 10 billion? trillion? I really have no idea.
If wikipedia has 2.5B words, let's generously assume 10B words. Let's allow phrase lengths of 1-10 words and arrive at 100B combinations.
Optimistically we're at 37 bits, not even a 7 character [a-zA-Z0-9!@#$%^&()].
And unlike the [a-zA-Z0-9!@#$%^&*()], we could madly cut that down based on frequency and popularity.
Therefore existing phrase passwords are security through minority. If they are adopted, they provide at best an order of magnitude or two over simple dictionary words.
But we're kidding ourselves, most people still use 'password'.
The word list is signed but for someone unfamiliar with crypto an electronic signature is useless while a lock in the address bar is reassuring.
BIP0039 has been around for a while and generates passphrases strong enough to be the seed of every private key you will ever deterministically generate in a wallet.
"Unfortunately there doesn’t appear to be user-friendly software available to help people generate Diceware passphrases"
This is silly. There are popular applications for every major phone OS that implement Diceware. Does anyone feel that they're untrustworthy?