Edward Snowden’s Advice for an Unhackable Password
time.com
time.com
I also have it written down because I figure if someone has access to my personal computer physically, and they want my passwords they can probably install some keylogger or something else I don't understand, and this way I'll never forget my password. I also have a list of services that I am signed up for so I don't forget to change my reddit password because I haven't used reddit in the last three weeks after something like heartbleed happens. What I will not do is store my passwords in my browser, that seems like an awful idea. Especially because some things automatically sync across browsers.
The serious browser extensions that do this use encryption for syncing, you are correct that centralizing them all in a browser extension is a negative for security, but the upside of having random and different passwords for each site or service _far_ outweighs the risks posed by centralization or browser storage.
The odds that one or more sites you use end up leaking your plaintext passwords is far more likely than Lastpass being hacked, even the odds of someone identifying your self described insecure pattern from a series of these leaks is far more likely than getting burned by an extension.
I had my apprehensions before starting to use a password manager, but after six months I consider it absolutely essential and urge everyone else to use LastPass or a similar addon. The benefits massively outweigh the risks.
If nothing else, having this functionality built into popular browsers would increase public awareness of better password practices by at least an order of magnitude.
I'm not aware of anything similar being built into Firefox.
I'm not sure this is a fair generalization, especially without knowing the sites sthreet visits. Lastpass holds thousands of passwords and is probably a pretty big target for hackers. I don't doubt that they have great security, but nothing is guaranteed; one should at least admit that trusting Lastpass as a SPOF is a non-trivial decision to make.
Currently, someone just has to compromise your account on one third-party service in order to compromise every service you use (do you use Yahoo Messenger? I think all passwords are cleartext for that).
With LastPass, someone would have to compromise the (likely more secure LastPass service, or physically access your machine (and then compromise LastPass) in order to access your passwords. Seems just as easy to use, but more secure.
That being said, I find passphrases hard to take on myself. I tend to use a set of mildly complex passwords I've used for years across a number of services.
Apparently the new key to passwords is a secure password db that you only keep a master key to access and then paste the passwords contained into services as needed. I've given a few of them a try but even then personally I'm not comfortable having my passwords kept on an external service, even if I have the master password to myself.
"I still think that the standard should just become a 8-16 characters password limit with no other restriction."
It's very doubtful you'd type such a crazy-long password by hand, and if you have a password manager there's absolutely no reason to go beyond something like 256 bits of noise encoded as hex.
>common long sentence
Oh god no. Don't use a common sentence as the majority of your password. Don't try to be more clever than the password cracker. It's easy to get lists of common sentences and lyrics. Sure, a common sentence is better than a single special character, but it might only be as good as 3-4 random characters.
Assume the cracker knows your method, and go based on an estimate of entropy. So perhaps a random character is 6 bits, a random word is 12, and a common lyric is almost certainly between 20 and 30. Keep adding things until you have 80 or 100 or 128 or whatever your goal is. (I would strongly recommend not using 44 as your goal.)
Even 10 characters of attempted random is going to be better.
Maybe even 5, if they were going to use a song everyone knows.
Increasing the minimum size past a point doesn't help security, it just leads to people using low-entropy padding methods.
Whether a sentence is better than "no restriction", I'm not sure, but that's not a very fair comparison because you can't force them to use a sentence either.
I'd say what you should recommend is a series of words that don't make a sentence, but where they can remember a scenario.
Or you could have the computer generate random words and let them make a sentence out of them.
But don't use a preexisting sentence, or a tiny modification to one. It will be far weaker than it should.
You can't enter certain characters in input type=password fields on web sites, such as null or CRLF
Max length for bcrypt is 50-72
Incredibly long passwords could DOS your site
They don't need to permit arbitrarily long passwords, just ones that are long enough.
I do worry about someone analyzing each and every change to the database for some kind of information leak, but I also change the compound key every 6 months which should help.
Yes, I've backed things up, saved my contacts, etc. But insofar as a password manager is supposed to be a comprehensive solution, it's a solution that forces people to choose between their Chromebook and their password manager.
My Google account has a strong-entropy, memorized password. So does my password manager.
That has covered all my usage cases, anyways.
"ILikeToPluckStringerdInstrumentsWithAPlectrum"
Snowden emphasizes using words that aren't in the dictionary, but proper names of historical figures are in certain e-dictionaries (my android keyboard's auto-complete dictionary for instance includes Margaret and Thatcher).
I always >sigh< when I have to resort to external web search and limit the search to that domain which usually gives in poor results.
( Just noticed they have added a note about that. )
Use incorrect answers for secret questions (wallet too).
If you steal my credit card, I'll just call my bank and cancel it (and I'm not liable for any charges you made, anyway). But if you break into my email (or even something like my Facebook, which might have weaker security), it might be really hard to recover from that.
* If they allow all printable ASCII chars, that means
128 / lg(94) = about 20 characters
* If they only allow alphanumeric,
128 / lg(62) = about 22 characters
If the site doesn't let me use a password > 20 characters, I don't sign up.I also use a password manager, so all my passwords are randomly generated.
My master password? 64 characters of line noise I memorized years ago. ;)
Also:
Any recommendations?
Key points being security and cross platform accessibility.
I've been using Dashlane http://dashlane.com for the past year and it works great across all browsers, iOS, Android, etc. Similar to other services it gives you a "security score" across all passwords to let you know if you're using insecure or repeat passwords and also reminds you to change your password when a service has been hacked.
I think I read this one, which evaluates the PasswordSafe database format as the strongest (but does not say anything about the program itself): http://www.6nelweb.com/bio/papers/pwvault-ESORICS12-ext.pdf
I'm still using KeePass because I like the program a lot more than PasswordSafe, which is a little clunky. There's a KeePass implementation for iPhone, too. Those two things have kept me using it.
Does anyone know the security implications of this?
nobody's proved it wrong, but BS said not to, so people avoid it.
Using words is okay, but you have to impress on people two critical things.
1. random words. not sentences. use a program or dice.
2. Each word is only as good as two random characters. 8 words is as good as 16 characters, no more.
People try to get 'clever' and it never works out well.