What's new

Password rant.

macpro, you realize that you've just made the job of cracking your passwords quite a bit easier, right?



nope, even with the algorithm you will not be able to guess mine lol the combinations are damn near infinite. good luck good sir.
 
Ok,

so I work for a large finance company.. and we obviously work with a lot of vendors. One of the vendors just changed our password for a program I need to access daily. And it went from being a word with some numbers, to looking like a cat fell asleep on a keyboard.

They should let me choose my own password. If I decide to make my password "password" that's my own sh*tty decision and they should let me roll with it.

/rant


I disagree... being a sysadmin, I deal with passwords (and users with bad passwords) all the time. If something needs security, a password can help to some degree if it is somewhat complex.

So use a password safe or something similar (with a secure password or PIN on it that you won't forget) Keepass is free and does a decent job.
 
Oh I understand the need for it. But my passwords are very secure in themselves.. and they're easy to remember for me. Unlike ^&@Fg#$$$@*
 
macpro, you realize that you've just made the job of cracking your passwords quite a bit easier, right?
nope, even with the algorithm you will not be able to guess mine lol the combinations are damn near infinite. good luck good sir.

More like a billion or so, which is, what, 30, maybe 32 bits of entropy. Anywhere between minutes and days, depending on the hardware available. I *assume* that your actual algorithm is some variant of what you proposed here, so multiply by maybe 10 to test variants. Then cut that in half for the "expected time to crack".
 
MacPro... I teach my users something very similar to what you posted... good to see that posted that way! I may swipe it!! lol!
 
MacPro... I teach my users something very similar to what you posted... good to see that posted that way! I may swipe it!! lol!

go right ahead! its what we use on our end of admins of the servers/equipment and what we try to teach the customers themselves as well lol
 
Oh I understand the need for it. But my passwords are very secure in themselves.. and they're easy to remember for me. Unlike ^&@Fg#$$$@*

All of my personal internet passwords are totally random and usually 20 to 30 characters (of all types). I couldn't remember them if I tried... as they are different for every site. I used to use passwords I could remember, but with all the "Bad Crap" out there... I decided to take it a little more seriously.

Password safe... I love it. Have the same one on my Iphone, Ipad, Android, and all my PC's (even my Ipod). I just sync them occasionally and that way, I always have my passwords with me no matter where I am. Copy and paste rocks... and the security is setup to automatically scramble and then delete the databases if three wrong entries are put in.... so pretty secure too. (I have several hundred passwords) :)
 
macpro, you realize that you've just made the job of cracking your passwords quite a bit easier, right?
nope, even with the algorithm you will not be able to guess mine lol the combinations are damn near infinite. good luck good sir.

More like a billion or so, which is, what, 30, maybe 32 bits of entropy. Anywhere between minutes and days, depending on the hardware available. I *assume* that your actual algorithm is some variant of what you proposed here, so multiply by maybe 10 to test variants. Then cut that in half for the "expected time to crack".

Then please, instead of saying you can prove me wrong, actually prove me wrong and crack my password :) like I said, good luck.




The safe way to keep yourself safe and your passwords safe 100% is to.. just... well, stay off the damn computer and internet. Good luck with that. Highly convoluted passwords that companies think are safe are no more safe than the algorithm and variants of that algorithm I posted above. Its a nice algorithm that is easy to remember and is secure on a lot of standards.

In regards to mine, I use that algorithm, with a minor tweak, but that is the base algorithm.
 
Then please, instead of saying you can prove me wrong, actually prove me wrong and crack my password :) like I said, good luck.

Aaaaand right on cue, the expected reply. Here's a quick lesson in how passwords work for everyone:

-----

The normal way you do this is you don't store the user's actual password anywhere. You calculate a big giant number based on the password, in a predictable way, with the property that the calculation is is relatively cheap to perform, but so that if i have the big giant number it's very very hard to guess what password might have produced that number.

This is one-way-hashing. Keywords: MD5, SHA-1, SHA-256 for further research.

Now, when I try to log in, I type in my password. The web site or whatever does the calculation on whatever I typed in, and compares the resulting number to the number it stored away. If they're equal, it says "great! You typed in the right password! Welcome!"

Why the heck do we bother with all this crap? Well, sometimes bad guys break into the web site and steal the database. If we just stored the passwords, they're just have the passwords for everyone and that would suck. This way, they just have a pile of big giant numbers that are very hard to turn back into passwords. Having the number is useless for logging in.

If we were not worried about the bad guys stealing these big giant numbers, we wouldn't have to do anything much for passwords. All you have to do is limit how fast someone can try passwords out. If you say "dude, that's three bad passwords in a row -- come back in 10 minutes" then you're not inconveniencing users at all, and you're limiting the bad guys to trying out 432 passwords a day. You can tell people to use practically anything for a password and it'll be good enough. Avoid words that start with A, and that'll get you most of the way there.

So, we have complicated passwords because we're worried about the security of our database of big giant numbers, the so-called "hashes". These are, in fact, a MAJOR target for bad guys.

Once you've stolen a set of hashes, you don't even bother trying to reverse them. What you do is you test passwords on your own computers, really really fast. Way faster than 432 a day. Way faster than 432 a second. More like a million per second. So the first thing you do is you try every word in the dictionary, with every possible combination of upper and lowercase. That'll take a couple of minutes. Now you go to work on algorithms that add a digit, or two digits, or four digits. If some dolt has given you his algorithm, you try that one out first. If his algorithm produces a billion possible passwords, that'll take about 20 minutes.

If you simply had to try out every single combination of upper and lowercase letters, digits, and various punctuation, that's gonna be more like 600 trillion combinations, which will take more like 20 years. This is why truly random passwords are stronger than any sort of algorithmic mucking about with a single word and a few digits.

-----

Now, finally, we get around to why I'm not going to crack macpro's password for him.

Remember when I said that you have to steal the hashes, the big giant numbers, for any of this to work? That part is ILLEGAL. It's A CRIME. Which is why I'm not going to break in to TPF and steal the hashes and spend 20 minutes to tell macpro what his password is. I'm not a criminal.
 
The summary is, anyways, the right answer for password security in today's idiotic world:

- use randomly generated passwords of pretty decent length (8+ characters)
- store them in a password safe that is itself protected by an easily remembered but quite long pass PHRASE, 5 or more words and not some common quotation and not "correct horse staple battery"

This should give you protection from most computational attacks for another.. decade, perhaps. Barring certain specific breakthroughs which would screw everyone pretty thoroughly.
 
Then please, instead of saying you can prove me wrong, actually prove me wrong and crack my password :) like I said, good luck.

Aaaaand right on cue, the expected reply. Here's a quick lesson in how passwords work for everyone:

-----

The normal way you do this is you don't store the user's actual password anywhere. You calculate a big giant number based on the password, in a predictable way, with the property that the calculation is is relatively cheap to perform, but so that if i have the big giant number it's very very hard to guess what password might have produced that number.

This is one-way-hashing. Keywords: MD5, SHA-1, SHA-256 for further research.

Now, when I try to log in, I type in my password. The web site or whatever does the calculation on whatever I typed in, and compares the resulting number to the number it stored away. If they're equal, it says "great! You typed in the right password! Welcome!"

Why the heck do we bother with all this crap? Well, sometimes bad guys break into the web site and steal the database. If we just stored the passwords, they're just have the passwords for everyone and that would suck. This way, they just have a pile of big giant numbers that are very hard to turn back into passwords. Having the number is useless for logging in.

If we were not worried about the bad guys stealing these big giant numbers, we wouldn't have to do anything much for passwords. All you have to do is limit how fast someone can try passwords out. If you say "dude, that's three bad passwords in a row -- come back in 10 minutes" then you're not inconveniencing users at all, and you're limiting the bad guys to trying out 432 passwords a day. You can tell people to use practically anything for a password and it'll be good enough. Avoid words that start with A, and that'll get you most of the way there.

So, we have complicated passwords because we're worried about the security of our database of big giant numbers, the so-called "hashes". These are, in fact, a MAJOR target for bad guys.

Once you've stolen a set of hashes, you don't even bother trying to reverse them. What you do is you test passwords on your own computers, really really fast. Way faster than 432 a day. Way faster than 432 a second. More like a million per second. So the first thing you do is you try every word in the dictionary, with every possible combination of upper and lowercase. That'll take a couple of minutes. Now you go to work on algorithms that add a digit, or two digits, or four digits. If some dolt has given you his algorithm, you try that one out first. If his algorithm produces a billion possible passwords, that'll take about 20 minutes.

If you simply had to try out every single combination of upper and lowercase letters, digits, and various punctuation, that's gonna be more like 600 trillion combinations, which will take more like 20 years. This is why truly random passwords are stronger than any sort of algorithmic mucking about with a single word and a few digits.

-----

Now, finally, we get around to why I'm not going to crack macpro's password for him.

Remember when I said that you have to steal the hashes, the big giant numbers, for any of this to work? That part is ILLEGAL. It's A CRIME. Which is why I'm not going to break in to TPF and steal the hashes and spend 20 minutes to tell macpro what his password is. I'm not a criminal.

Great explanation, it really is. I think the point here is being missed.

While I understand all this and agree with this, the average John Doe isn't going to go through the amount of work it would take for "the most secure password for every site he/she logs into." Lets face it, the group of us that do use password vaults like mentioned above are very very few of us, unfortunately...

Also, it doesn't take long for a company to realize they've been breached and then to send out an email to its users saying they should change their password, and the users who are on the ball on these things are pretty safe.

Now, your explanation (which I did actually enjoy reading) and reasoning above, is best put in practice in situations such as the OP's, dealing with larger companies with a lot of sensitive data between clients (think banking... high value targets) is where these types of passwords do come into play and strongly needed. And a lot of those companies are adopting the password generator key fobs (one of my clients has about 5 of these for 5 different accounts) where the same algorithm/hash is stored on the server and the key fob, the passwords change say every 15 minuets and they are always in sync.
 
I completely agree that strong passwords are needed. I just hate the ones they generate and I'm forced to use.

Although for things like ordering beef jerky on the internet.. I shouldn't need a 15 digit password with some characters required in wingdings.
 
I completely agree that strong passwords are needed. I just hate the ones they generate and I'm forced to use.

Although for things like ordering beef jerky on the internet.. I shouldn't need a 15 digit password with some characters required in wingdings.

haha, agreed, but if its your credit card info and stuff... usually that stuff can possibly be tied to that database and password you use.

Plus, they generate them for you because you would choose (and so would everyone else) a weak password like "password." Yes, I have seen this in the work place far to often...



And nice little article. Pretty much summed up everything being talked about right now lol
 
Yes its crazy. I am a software developer by profession, changing password to "password" might sometime screw up system if it is not properly coded. :)
-Mithil
https://www.facebook.com/MyGlassEye
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Back
Top Bottom