Deloitte: Use a Longer Password In 2013. Seriously.
clustro writes "Deloitte predicts that 8-character passwords will become insecure in 2013. Humans have trouble remembering passwords with more than seven characters, and it is difficult to enter long, complex passwords into mobile devices. Users have not adapted to increased computing power available to crackers, and continue to use bad practices such as using common and short passwords, and re-using passwords across multiple websites. A recent study showed that using the 10000 most common passwords would have cracked >98% of 6 million user accounts. All of these problems have the potential for a huge security hazard. Password vaults are likely to become more widely used out of necessity. Multifactor authentication strategies, such as phone texts, iris scans, and dongles are also likely to become more widespread, especially by banks."
correcthorsebatterystaple. It's a perfectly long, easy to remember password. Just, nobody use it other than me, ok?
I used my online banking today and they limit to 8 characters EXACTLY... even though they demand a non alpha-numeric character and mixed case. I keep thinking, these idiots still don't get it. Also, obligatory.
If computers were people, I'd be a misanthrope.
But it takes much longer to type in
The Tao of math: The numbers you can count are not the real numbers.
There's going to be a shift from passwords in general. Not only are they often insecure, but there's no verification that the person typing in the password is the user who owns it.
No, we're going to switch to biological means. This will be more secure, but as a side effect, there will be more assaults in which the eye/finger/penis is removed and used to gain access to these bio-protected systems.
Don't use a longer password, just use two factor authentication.
hunter22
We should have legislation prohibiting cleartext and unsalted password storage. At least for any site that handles money. That will help quite a bit to inhibit the sort of casual database cracking that goes on today.
I am becoming gerund, destroyer of verbs.
It sounds like Deloitte has been partying like its 1999.
I'll change it to 123456
The relationship between password length and password strength is old news.
But don't tell users, tell the programmers and system admins. I regularly encounter systems where max password length is 12 or fewer characters. For some reason there are also systems that don't allow characters other than letters and numbers in passwords.
Let us make longer, more secure passwords. Let us use special characters, unicode, tabs and spaces!
dongle hangin!
We play the game with the bravery of being out of range
I'd be more than happy to use long, more secure passwords if I'd be allowed to let my device memorize them. More and more sites are using the HTML option that denies autofill, keeping devices from memorizing passwords on them.
It should be possible to tell a device to ignore that HTML option if you have a passkey set on the device. Not letting devices remember passwords is less secure than just allowing it because people will use weaker, easier to type in passwords.
Not to mention Google's bad habit of making you reenter your password every so often. Just keep me logged in, damnit. My phone has a passkey.
Some password requirements are perfectly acceptable, even encouraged. There exist plenty, however, that just make one scratch one's head. Why would a maximum length any lower than several hundred characters ever be necessary? More egregious limitations include requiring an insanely complex number of symbol/letter/number combinations (easy for AI, hard for humans, as XKCD eloquently points out) and, of course, passwords restricted to numbers only. Sadly financial institutions seem to be fond of this one, possibly under the mentality that a PIN is just as good as a password, and customers won't forget that!
ÂHumans have trouble remembering passwords with more than seven characters, and it is difficult to enter long, complex passwords into mobile devices let's say you type your current 7-char password 2 times, is it harder to remember? I guess it will be even harder to remember to type it 3 times, if 14-chars are no longer safe enough in the future.
I think some places encourage short passwords. StudentLoans.com is Citibank's site for, you guessed it, student loans. The MAX password length is eight characters. That only encouraged me to pay off my loan to them faster just so I wouldn't have to deal with security like that.
Of course, nowhere in the signup do they warn you that only the first eight characters of your password will be accepted, nor does the login box limit you to inputting eight characters. I signed up with abcdef12345678 and tried signing in with abcdef12345678 but it gave me password refused. By luck, I tried abcdef12 and it worked. Screw Citi and all of the others still using password schemes from the early 90s
We should encourage the use of longer passphrases rather than passwords and eliminate or raise limits on their length. It's much easier to remember a sentence than a string of random characters.
Too many banks in the US also have limits on both user names and passwords. :(
The problem with this is that most people demand to use an easy to remember password and will stubbornly ignore their own password hints. This happened quite a lot at a fashion company I worked for (I wasn't responsible for the web end, thankfully), and customers kept complaining, no joke, "why should a password be case sensitive?"
It wasn't uncommon for customers to blurt out their passwords on the phone either. One lady started giving me her credit card number out of the blue, thinking that was the problem. When these are the types of people you're dealing with, the lockout is quite a bit more of a hassle. I think they switched to OAuth as a result.
People are getting used to the idea of online security, but growing pains are plenty.
If computers were people, I'd be a misanthrope.
Probably not. I can type my mis-spelt Shakespeare quote of a passphrase faster than I can type an obtuse non-alphanumeric-laden password, because I'm far better at typing English sentences than I am weird symbol sequences.
Just because you're paranoid doesn't mean there isn't an invisible demon about to eat your face
We should have legislation prohibiting cleartext and unsalted password storage. At least for any site that handles money.
Personally, I'm surprised PCI doesn't require this already.
An enigma, wrapped in a riddle, shrouded in bacon and cheese
Because a lot of websites, especially financial sites, have stupid limitations on password length and/or complexity.
Passphrases are uncommon because many sites think that "at least" means "exactly" when setting up the user database.
I've dropped one bank because of it. And those secret question/answer fields that are also 8 characters long because they might waste entire megabytes of storage if everyone had room for a complete response.
Only if you hunt and peck for everything.
FWIW, it took me about half the time to type the above line than it takes to type my current 12 semi-random character password.
An enigma, wrapped in a riddle, shrouded in bacon and cheese
Instead, store your password on a TPM chip, from where the hash can not be stolen and where the attempt rate can be regulated. This way even 7 character passwords can be quite secure.
passwordpasswordpassword
Have gnu, will travel.
... and don't give me that 'muscle memory' crap, if you're rotating passwords like you should, muscle memory doesn't even come into the picture.
An enigma, wrapped in a riddle, shrouded in bacon and cheese
Use keepassx. Usernames and password won't be stored into your browser and that could be annoying but you'll always be able to paste them into any login form. Or at least I never experienced any problem. There is also an Android version and you can copy the password db file among devices (dropbox or manual file copy).
Same thing for my boss...I insist that he uses long advanced passwords, but he's old and hates complex things in life, likes to play music and sing...and yet he runs a 6 digit company, the worst part is that he uses his silly easy passwords on hundreds of sites.
What this world is coming to - is for you and me to decide.
If 99% of sites didn't put such a restrictive short length on their password length. I can remember and don't mind typing a pretty long sentence, but then the site generally complains because of the spaces or because I exceeded something silly like a 33 character limit. I will also say that some forbid special characters, some require. If you are going to stick me with no more than about 12 characters and refuse use of symbols like & and $, it's asinine. If you see that I have a 48 character password and complain that not one of them is 'special', you are impairing my ability to use a memorable password of appropriate length...
XML is like violence. If it doesn't solve the problem, use more.
Password length matters to brute force attacks - and if your application allows a brute force attack to happen, it is broken already, insecure by design.
Enforcing longer passwords will not improve security for real-life cases. Enforcing more cryptic passwords will actually reduce security for real-life cases. Why? Because people will need to type slower, making shoulder-surfing easier. People will start to write passwords down, and they will re-use passwords more often.
You can't solve this issue with simple solutions like "use longer passwords". The only thing that will do is make "password1234" the new standard instead of just "password".
Assorted stuff I do sometimes: Lemuria.org
Two reasons:
Firstly, because the attacker may not need to authenticate against the server, if they have managed to hack in and get the encrypted password or found a way to determine it by MITMing a legitimate authentication.
Secondly, because what you describe is itsself abuseable for DoS attacks. It allows an attacker to simply log in repeatedly with a bad password to disable an account. Even if the account can be reenabled after some effort, that's enough to cause serious disruption in some fields. Lock the competitor's salespeople out on the morning of a big conference, or use it to delay members of an opposing MMORPG team while your own people storm their territory.
http://xkcd.com/936/
I knew there'd be a back door
Nothing has changed.
When applying a hash+salt to a password to store in a database, you run it a bunch of times to take up an attacker's cpu time. By picking the number of repeated hashes, processing a password->hash attempt can be made to take any amount of cpu power. When designing a system, one attempts to choose a value such that, with current systems, it takes a reasonable amount of time to process a login but also too long for an attacker to brute force.
TFA talks a lot about the 'number of possible combinations', but in reality that is not strictly relevant.
What matters here is only how much more cpu power is available to attackers than to the site owner. This ratio is what determines the number of 'combinations' required to defend against attack by someone who steals the database. So, if attackers start using hardware to run hash algorithms, sites can as well, and the same balance would be maintained.
I've got logins for what... 200 sites? This is a problem for the sites, not me.
Passwords don't work. Think of something new. I can not remember 200 passwords that are 9+ characters, can't contain real words, have special charcters and God knows what else.
The solution for the end user? Don't use these sites for anything important. Don't store and personal information. Don't do business with sites that retain your credit card number and give you no option to not store it.
I speak all my passwords aloud into either my desktop microphone, laptop microphone or mobile microphone. This allows me to use the longest phrases without having any difficulty typing. People get a bit annoyed when I'm using the computers at the library but I explain it's all in the best interest of security.
Join the Slashcott! Feb 10 thru Feb 17!
No, but LastPass does!
Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
So this (just use an 8 character password) is for sissies. I also don't write my passwords down and they include special characters, large and small letters, numbers, and are completely random. It's not possible to crack a 25 random character password. I suggest everyone follow me and use 25 characters at least.
Every damned time you turn around the iPhone is asking you to enter your password for iTunes. And with the on screen keyboard it's torture to actually enter a password with mixed case, numbers and (heaven forbid) symbols.
I, for one, do not look forward to our excessively long password overlords.
Is it just my observation, or are there way too many stupid people in the world?
Bank of Montreal's passwords for online banking must be exactly 6 characters long, and contain no special characters.
Password length matters to brute force attacks - and if your application allows a brute force attack to happen, it is broken already, insecure by design.
Enforcing longer passwords will not improve security for real-life cases. Enforcing more cryptic passwords will actually reduce security for real-life cases. Why? Because people will need to type slower, making shoulder-surfing easier. People will start to write passwords down, and they will re-use passwords more often.
You can't solve this issue with simple solutions like "use longer passwords". The only thing that will do is make "password1234" the new standard instead of just "password".
You should get 10 chances to enter your password and then your data should self destruct if encrypted.
After three tries, the account is locked and you then have to go through a bunch of Q & A to get it unlocked?
As for those short passwords with the stupid rules. UGH! I can't remember them. Let me use a whole sentence!
... before I'll submit to an iris scan at a bank. Several local banks have tried using thumbprints on checks, and it is NOT well-accepted by their customers and others.
FTFA "Password vaults are likely to become more popular for managing multiple accounts and minimizing password re-use, but they will require strong multi-factor authentication." Make sure that vault comes from a trusted source... Who's that?
I typically use a 25 character password as an absolute minimum. I memorize the whole thing and it's easy for me to remember this stuff for some reason (I must be gifted). I don't remember it at first but when you gotta type something in every few minutes to install anything or do anything you remember it.
I haven't had a reason to use a 48 character password but I would have no problem remembering it if I needed to. Linux for example does not seem to put restrictions on the length of your root password or your passwords for certain things. But certain websites are ridiculous. They want to practically tell you your password by restrictions. You can't use too many of this letter or that, you can't use a password longer than this but shorter than that, for fuck sake why don't they just give me my one time password to my email address which is secured by at least a 25 character password and be done with it?
But passphrases are not going to be magic bullet. A website that claims to be secure should actively try to crack passwords and tell users which are weak. One time pads, i.e. texting to phones a code, is also a highly secure procedure. But users forget their phone, and websites have to have something to get around the security. Which is always the issue. Sites always have to have a means to get around the security.
"She's a scientist and a lesbian. She's not going to let it slide." Orphan Black
That's a bummer. I always use 12345. Knowing this, I'm changing it to 1234567890.
to teach people easy to remember passwords.
Examples:
All you kids, case appropriet, change vowels to numbers.
First line of you favorite poem, backwords with vowel substitution.
Hell: 1_L1k3_B1g_Butt5
The Kruger Dunning explains most post on
This strikes me as largely a non-issue caused by poor login security design.
Why not simply code the authentication such that for every successive request that fails to a given account, an enforced delay of, say, the square of the number of sequential login failures to that account, in seconds, is applied before the next attempt?
This would allow for actual humans to make several errors at an slowly-increasing wait each time, whereas for a scripted attack, after 200 tries we're up to 11 hours per try and growing fast. It seems that a brute-force attack becomes entirely unlikely to succeed under these conditions.
Standard Linux distros interject a delay between login attempts, why isn't this considered basic and expected good design for all login authentication contexts?
~ Whence do you come, slayer of men, or where are you going, conqueror of space?
I used my online banking today and they limit to 8 characters EXACTLY... even though they demand a non alpha-numeric character and mixed case. I keep thinking, these idiots still don't get it. Also, obligatory.
There is really no reason not to use one time passwords for banking. The bank can email you a new password or text it to your phone every time you verify your identity with them.
Only one way to tell if you're password is truly secure, some techniques may be less obvious than others, but I like this one cause it shoves them in your face:
http://www.passwordmeter.com/
You can also theorize how long it would take to crack your password here:
http://daleswanson.org/things/password.htm
Of course, you can also always grab a copy of ophcrack (windows users... most of you) : ophcrack.sourceforge.net/ and test it out for yourself, just remember it's YOUR hardware that's testing the password, not a botnet.
So if I want to wipe out your data I just attempt to log in to your account 10 times using a bogus password. Even if your data's backed up, the next time you go to log in might not be a great time to have to do a restore.
That's one way to prevent people from using 'Password' as their password.
The Kruger Dunning explains most post on
Don't use a longer password, just use two factor authentication.
Use more than two factors and generate a one time password.
I would use longer passwords, but multiple sites like to limit passwords to arbitrary lengths like 14 and 16 (live.com and slashdot.org last time i checked). What reason is there to have any password length limit (other than arbitrary passwords of like 100kb of data) if they should be storing them as salted hashes?
http://www.baekdal.com/insights/password-security-usability back in 2007. I don't deny that Randall Munroe has summarized the method very, very well however. I also wouldn't be surprised if he was familiar with Baekdal's article. So of course it's not just length alone, it's 3 or 4 common or uncommon words, with spaces acting as special characters. Please, read it. I think Baekdal understands this very well, both user-side and server-side. It may not be watered down enough for the non-tech layman to understand, but I think it's very well-written for anyone tech-savvy. And yes, he basically agrees server admins have a responsibility, too-- good password user policy, salt and hash on password databases, etc.
The only reason to restrict password length is to facilitate an inside job. Passwords should go up to 300 characters.
I created a 300 character password for the hell of it in Linux. It was fine but so inconvenient to type that I switched to 30 or so. Also there is no real security benefit beyond bragging rights of being able to memorize garbage like those people who memorize Pi.
batmansupermanspidermanwonderwomanrobingandalfgolemgreenlantern
Use keepassx. Usernames and password won't be stored into your browser and that could be annoying but you'll always be able to paste them into any login form. Or at least I never experienced any problem. There is also an Android version and you can copy the password db file among devices (dropbox or manual file copy).
Keepass doesn't work for certain sites. Certain sites still make you type everything in character by character.
There have been a few stories in the last year or two with analyses of stolen password databases. The overwhelming majority of the passwords were based around a few simple schemes like abc123, ABC123, 123456, etc. Wouldn't it be possible to simply not let users choose those passwords? If you know what the 10,000 most common passwords are, you can hook the list into your account creation routine and reject them. Seems like an big improvement for very little effort on the user or server end.
Visit the
This.
My bank (not named to protect the guilty) has the following restrictions on password:
-Maximum 8 characters
-No special characters
-Case insensitive (they don't tell you this, I only found out after fat-fingering my password and it still letting me in)
I have complained multiple times to multiple people on different levels, and still nothing. The response was "If your account is hacked, it is because you have viruses on your computer". Sure, a keylogger is the most likely avenue for attack, but why make brute forcing easy?
My data is backed up to the cloud. Try wiping that.
Deloitte predicts that 8-character passwords will become insecure in 2013
I'm gonna say he hit the nail on the head there since 22 letter passwords were insecure in 2012.
Everything is insecure, every month we need to change the password, use a better password, use a better username etc.... Here is a new concept, lets only use biometrics that are also paired with a one time pass, the encrypted entry is generated at access time and is valid for 20 seconds and if you miss it your locked out for 24 hours no matter what. That would be secure, anything less by next month will be insecure.
You can compare the hash of what the entered to a rainbow table of most common hashes and not allow those.
The Kruger Dunning explains most post on
So if I want to wipe out your data I just attempt to log in to your account 10 times using a bogus password. Even if your data's backed up, the next time you go to log in might not be a great time to have to do a restore.
Also I would be tipped off that someone is trying to access my data if it's destroyed. Basically if you have precious data then back that up to the cloud and the rest of it you should care more about privacy of the data than the data itself.
Forcing people to change their password to comply to "their" rules only makes passwords weaker.
Users should be teached to create passwords with a formula or pattern for each separate site or service and to NEVER EVER use the same password twice.
For example, name of the site, year of signup, a non character and a non guessable unique postfix: slashDot2012@noncoward
And no, this is not my formula nor my password, heh...
Also, strictly reinforcing policy forcing people to change it every X weeks, will eventually lead to people writing it down on a post it and stick it underneath their keyboard or even on a visible place. Just walk through an office and look around.
Google gets it, I have the same password since signup, years ago. They warn sometimes, but you can click that away without forcing you to change it or else you cannot login. When a site or service forces me to change my password, they essentialy tells me they are insecure about their security...
KERNEL PANIC -SIGFAULT AT ADDRESS #51A54D07
His password:
" I_Like_To_Play_Misic_4_u."
The Kruger Dunning explains most post on
Its actually a good question.
Make it 12 characters long. Now you don't need case sensitivity.
The Kruger Dunning explains most post on
Password vaults are likely to become more widely used out of necessity.
BULLSHIT! If my password was omgponies1 then my new password is now omgponies1omgponies1. I can remember it and you can't crack it.
The thing you have is the phone, not the generator, so it is two factor.
The replaces the phone with the specific computer as "the thing you have". Still two-factor.
"Most organizations keep usernames and passwords in a master file. That file is hashed... master files are often stolen or leaked. A hashed file is not immediately useful to a hacker, but various kinds of software and hardware can decrypt the master file and at least some of the usernames and passwords. Decrypted files are then sold, shared or exploited by hackers."
Many websites these days allows you to try 3 passwords, then requires captcha and/or waiting period, possibly combined with email, etc...
In these cases password size doesn't matter
In fact it only matters if the hash of the password is publicly available or the password is used for encryption of sorts. This is not common for websites.
Why not fit PCs with an automotive style ignition lock? You could have just another car key on your keyring. Modern ones have embedded codes. You could even go farther and embed an RSA-style code generator in the key. You wouldn't need a display or a button to press, since you're downloading a code to the ignition lock anyway.
Do not mock my vision of impractical footwear
My solution would be to allow for each user to select a self destruct sequence option where if the hashes do go missing and this does occur that their data will be destroyed in this case so that hackers have no chance of accessing it. Some people would rather destroy the data than let it get into the wrong hands.
What about a variant of Rodney McKay's password from Stargate Atlantis? "16431879196842" -- use the year of Isaac Newton's birth, the year of Albert Einstein's birth, your birth year, and the number 42. You could swap out the birth years of other famous supergeniuses and even add a third person for added security. I bet CowboyNeal uses the birth years of CmdrTaco and his mom for his password,. . . ;-)
I at least try to use better passwords for more important logins. I don't waste brain power or worse resuse high quality passwords for sites where it really doesn't matter if my account gets hacked.
The annoying trend I see that the sites that most often enforce "better" passwords are the ones I don't care about. Must have at least one upper and one lower character, must have a non-alpha numeric character, no more than two consecutive characters: All this just so I can post to a web forum. Meanwhile the bank will accept almost anything.
I don't think people have quite got the implications of google's new headwear (Project Glass). Others have gone before - but Google have shown they can push into the mass market.
I think you should assume from this point forward that anyone wearing eyewear is recording everything they're looking at in sufficient resolution and frame rates to play back your typing later and thus discerning your password.
Previously you'd call this "shoulder surfing" - but they human eye doesn't really do "zoom". Digital zoom from digital eyewear, on the other hand, means your password could reasonably be read off your moving fingers from a bus-length away.
A second factor is now a requirement, IMO. Interesting times.
My bank (not named to protect the guilty) has the following restrictions on password:
Name and shame away! Stupid password restrictions like that is a telltale sign that they are storing your password in plain text. Probably on some really arcane or buggy system if it doesn't even handle case-sensitivity correctly. The only way that companies are going to get their act together is if customers change to a competitor because they are fed up with crappy account security.
Football Odds
Verified by Visa is like this with the added hassle of asking for three specific letters from the password. This is bloody annoying as it means having to tick off letters on your fingers / some mental map to pick the right ones. Even if you have an eight letter word as the complete password who keeps it stored as a byte array in their head? It only adds security by irritation to the one person who is actually authorised to use the damned thing.
"Wait. Something's happening. It's opening up! My God, it's full of apricots!"
My voice is my passport. Verify me.
I use KeyPass to manage my passwords. The only password I need to remember is the one for KeyPass. I don't even know some of the passwords it uses. This should be a feature built into browsers.
It's 2155, and Daniel Vectorstar, our resident security analyst, states that everyone this year should keep their passwords to a minimum of at least 3 pages, single-spaced...
I'd tried accessing a 401k account with JP Morgan a while back and had to call their 800 #.
Interestingly enough, their voice system asked for my password. Not only had they dropped case out the window, but for each character in the password they'd also managed to condense from 3 letters and 1 number down to just 1 number.
No, but LastPass does!
...
2013, and still no viable way of punching someone via TCP/IP...
lol
An enigma, wrapped in a riddle, shrouded in bacon and cheese
Hell, make it 13 characters long (just add '~' at the end to indicate snarky,) that way all the haxxors will be confused because they didn't guess you were being snarky.
"Password vaults are likely to become more widely used out of necessity."
A long time ago I memorized my passwords. They started with simple six character passwords to more complex 10 characters. Later as complexity requirements became more disparate between systems, including aging and having to retire otherwise good passwords, I gave up and started saving them, instead.
I use the built-in password saver in Firefox with a master password and FIPS enabled (http://luxsci.com/blog/master-password-encryption-in-firefox-and-thunderbird.html) and with my user profile encrypted by Windows EFS. I use apg (http://www.adel.nursat.kz/apg/) to generate random passwords as long as 48 characters and with character sets dependent upon site requirements.
To my aggravation many web sites do not allow me to save my password. To mitigate this I have a bookmark button with Javascript code to strip all autocomplete=off from the forms. I get more aggravated with sites which have maximum lengths or do not allow certain special characters. So far as I know, if you hash what you get from the user it should not matter what is used for the password,assuming it meets complexity requirements.
Sure, I could get a third party password utility, but I feel that I should be allowed to use the built-in utilities available to me. While my way does have its weaknesses, and I know not everyone manages passwords much worse, the situation is no less aggravating.
We did solve this one already and it's called the iButton. The only place I've actually seen them used correctly is The UPS Store. The local one uses them for everything, locks, copiers, you name it. They have them in the wall, in the floor, wherever it's most convenient for them to be to relate to a particular function.
You can get a Java Crypto iButton which is pretty much what it sounds like, so not only can you get one with a crypto accelerator but you can actually upgrade the software that runs on it.
"You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
It's ridiculous for a bank to ever depend on a "Secret" question, anyway, unless that question is "what is passphrase number three". Asking what my pet's name was or what street I lived on as a child leaves me vulnerable to data mining attacks.
"You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
gabriel janice maximillian kevin patrice
That's 40 letters (including the spaces).
Or, the full name of my cat:
eric the ring tailed chickabeastie defender of the realm
I think it would help if we could use "forbidden" chars like { or or $ etc.
Shoes for Industry. Shoes for the Dead.
Verified by Visa is like this with the added hassle of asking for three specific letters from the password. This is bloody annoying...
Much more worrying that being annoying, it indicates they store your actual password, not a hash of it. Otherwise, they wouldn't be able to verify individual letters.
Why aren't passphrases more common?
The should be. I enjoy wordplay in the first place, and passphrases just allow me to mess with that. Sometimes for grins I throw in something obscene.
But for all the hoopla, it is pretty clear that Slashdot users and the world at large are severely separated. We're dealing in passphrases and computer generated randome number/letter/symbol sequences, while probably 80 percent of peoople out there are using Password1, or Letmein! or 1234567 other simple to crack passwords.
To the extent that I doubt there is much Brute forcing going on any more. Simply throw out some of the more likely passwords, and you are likely to catch something.
The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
Most awful password experience?
"Password must be at least 12 characters, with one number, one upper case letter, and one special character."
Thisis1passwordsystemthatsucks!
I had to call support when logging in for the first time, and then I learned that there is an unpublished maximum length. Wow.
I keep sending emails to company security admin people about their poor security practices, and I don't think they care.
Security questions?
Pictures?
Forcing some format?
Jeez... at least get with the freaking late twentieth century and let me use up to 256 characters...
Best passwords ever, and easiest to remember: Pick a song that's important to you, and use your favorite line. Ain't nobody going to guess which Celine Dion song I picked...
People still use 8 character passwords? Heh. I wish sites would allow us to log in using GnuGP encryption keys. Seems then you could have 1 password that's not really breakable. You'd only have to keep safe a couple files (the public & private key), like physical keys to your house or car. I think most people could handle that.... and it would really simplify password management.
---
The criteria that a lot of websites need:
- uppercase and lowercase
- must have digits
- must have some non-alphanumeric chars [many don't allow the full set but underscore is usually safe]
I created a very simple perl script to do this. Here are some generated passwords from common phrases that are 2-4 words in length:
12_kCq_wRb_xFn_205
16_pMj_rVd_yZl_sGd_221
37_lPp_dNs_gNr_S_99
193_mSh_rTs_cVs_194
104_mRt_pCn_T_105
109_lCn_lBd_D_180
55_mRt_tSn_kCr_pSf_nSr_S_186
The mangling isn't trying to be cryptographically hard by any means. I don't consider the mangling to particularly clever. But, these seem to me to be sufficiently strong passwords. I haven't run them over a PW strength assessment algorithm but they're stronger than PWs I've used at various websites that rate my personal ones as strong.
The groupings used here are deliberate as one PW in a group might clue in the other(s). If you'd like to take up the challenge, a few hints: (1) phrases you've surely typed before, (2) a common comparison, (3) part of a well known company logo/trademark, (4) an author, a novel, and the author's real name.
[If anyone's interested] I'll post the original phrases, the algorithm description, and the perl script [if I can figure out the html tag slashdot needs for unformatted] tomorrow as a reply to this post.
Like a good neighbor, fsck is there
I can admit immediately that I know incredibly little about this subject. So, I'm wondering if the cure for this issue is not necessarily longer passwords, but a different style of passwords? Ignoring the shear inconvenience of a model like any of the following, would they indeed solve the problem? 1) Require captcha every time we enter a password? 2) Include a captcha style word displayed on the page that is tacked on to the end of your personal password? (If my password is 'dogs1337,' and the captcha is 'gelmug,' the new password would simply be 'dogs1337gelmug') 3) Require two distinct 8+ character passwords? Any of the above would at least allow for a significant increase in possible password combinations if all we are worried about is the ability to brute force 8 character passwords. But, I suspect that might not be the only worry?
One of the reasons I find myself needing a password vault is the bizzare array of password policies out there today. Take Chase Bank, for instance, who only allow alpha-numeric characters.
But the worst part is often the why: In an effort to assist you in securing your password, some sites want to perform password validation server-side. Just stop and think about that for a moment. Why would a website exclude characters like apostrophe, percent, semicolon, etc, from a password field?
Well done: In order to assist your security today, I'll be storing your information alongside a plain-text history of your passwords - you can trust us! Now, obviously, if we allowed funny characters into those passwords, all hell could break loose. But by restricting you to easier to crack passwords, and then storing them in plain text too, the only risk is if we screw something up in the code that checks incoming passwords. We just proved we're smart enough to have already thought of that!
-- A change is as good as a reboot.
Probably not. I can type my mis-spelt Shakespeare quote of a passphrase faster than I can type an obtuse non-alphanumeric-laden password, because I'm far better at typing English sentences than I am weird symbol sequences.
Never did any assembly language programming, did you?
When our name is on the back of your car, we're behind you all the way!
What the blaze is a six digit company? Ranked in Fortune 999999, or something?
When our name is on the back of your car, we're behind you all the way!
Who in their sane mind (in ITSEC, that is) is still dabbling with brute force problems? Seriously, Deloitte, stick with economy audits, at least there you can't do much more harm than has already been done to this economy, but stay out of real work, will ya? At least we could do without your "recommendations" to your clients to require bizarre combinations of characters from their employees that only leads to them noting them down on a post-it and stick it underneath their keyboards (which, oddly, you do NOT have a recommendation against ... but I ramble).
Whether your password has 3 or 30 characters, and how many special characters in what odd combination and how many generations back you may not repeat even 2 of those characters again is moot. NOBODY on the "other side" bothers with brute forcing anymore. Passwords are being sniffed, hacked or simply lifted in other ways, from keyloggers to the good old "this is your IT-department on the phone, we need your password". And when I have your secretary TELL me her password, it's frickin' pointless to make it 100 chars long. Only means I have to talk to her longer. Which, I admit, may or may not be a nuisance to me when I get tasked with testing something you "secured". Depending on how nasty the voice of the person I audit is.
The security hole is NOT the length of your password. Get with the times, brute forcing just simply and plainly takes too long. Even if it's only a 3 char password, there are simply ways that get the attacker access far easier, more reliably and with a lot less effort.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
the bobs hive is not exactly the first place i tend to think of when i want to know about information security trends... maybe they should stick to their core competencies. like really busy powerpoint templates that the government likes and "anybody whoever built an empire..."
Wait, that's the combination on my luggage!
Am I the only person who generates easy to remember yet difficult to read / crack passwords based on things like movie / cartoon / book quotes or music lyrics? I don't think I have ever make a totally random password for myself and instead create easy to remember passwords from all sorts of phrases. The only problem with this is when sites disallow long passwords (so many limit passwords under 10,12,20 characters).
Take for example (random things off the top of my head) the sun will come up to morrow, to morrow. Tswcu2m2m. Or Dance your cares away Worrys for another day DycaWfad. Throw in a few !! or $$ at the beginning or ending and you're set.
TruePunk | Games
I only have to have a password stronger than yours.
What the blaze is a six digit company? Ranked in Fortune 999999, or something?
You seriously underestimate the size of the economy. A mom-and-pop store is a six-digit company...
"Little does he know, but there is no 'I' in 'Idiot'!"
There are a variety of workarounds for that problem.
Some I've seen are:
1. Browser plugin.
2. Bookmarket
3. Use of console to enter Javascript
http://superuser.com/questions/405877/is-there-a-browser-extension-that-bypasses-restrictions-of-pasting-passwords
I like that Google asks you for your password again for certain tasks. I don't tell my google password to anyone, but I do often leave my session open when I walk away (who doesn't?). I'm willing to take the risk that someone could get 5 minutes looking at my inbox, but I don't want to take the risk that the person could read my web history or change my password.
Prompting you again for these tasks makes perfect sense.
Last week I ran into the first site that actually REQUIRED a punctuation character in the password. My immediate thought was of the time a couple of years ago when I seemed to keep running into sites that refused to accept my firstname.lastname@gmail.com, address when I tried to register because no e-mail address would have a period in it.
Honestly it feels to me that the whole username/password regime is on its last legs, and is about to collapse under its own weight.
I really don't want biometrics, but I could certainly live with a minimal RFID/NFC key (just like my car, or maybe my phone) that would authenticate me on whatever machine I'm using. If we need something, I want it easy and portable. Maybe a pinky ring with embedded chip?
Meanwhile I'll stick with one long complex tricky password for sites that actually matter (like banks); and another short snappy one for stuff like slashdot and forums that don't (90% of places). About four times a year I change them both to keep stuff fresh.
For everything else my password is "Forgot password? Click here to reset."
Three Squirrels
http://xkcd.com/936/
At first, I used complex alphanumeric passwords.
Then some system asked me for some Case. So I added up some actual Easily Guessable Case.
Then some system asked me for some Sp#ci@l characters. So I added them (@g@!n e@sy to f!nd).
Then some system decided it didn't like Sp#ci@l characters. So I only added them when needed only
Then I tried migrating to Pass Phrases. However, the Sp#ci@l still needs to be there sometimes, and sometimes they don't like that, and sometimes, spaces aren't supported, and sometimes, there's a limit of 15 characters.
Then, I found one site that actually asked me for PRECISELY 8 characters, with mixed, number and special. The frag!
And I have two places where I need to switch passwords every now and then (3 months and 6 months)
So I freaking gave up. At home, my crap is seriously secure. It's long pass sentences with some mistakes in them, it's easy to remember them, and hard to figure them out. Whenever I can, I use these pass sentences, always different, because my brain actually remembers these passwords, and they are kind of related to the system in question, for example, on a Fruity system, I might write "I SIRIously love cider" ;)
Everywhere else, the "dick" sites and systems, I have 3-4 passwords, precisely 8 characters in length, with option@1 specials and one ever incrementing character somewhere... Because I need to remember these.
Oh and then, for crappy sites I couldn't care less about, I'm in the top 50 easiest passwords to find. Find them, I couldn't care less. :)
What the blaze is a six digit company? Ranked in Fortune 999999, or something?
You seriously underestimate the size of the economy. A mom-and-pop store is a six-digit company...
You haven't answered the question. what is a six digit company?
When our name is on the back of your car, we're behind you all the way!
Don't mistake inconvenience for security. A lot of security theater is very inconvenient, often on the premise that if it hurts more it must be working better. Real security improvements have little or no effect on usability, and can actually go either way easier or harder.
Beta is broken and the link to classic doesn't work. Stop wasting our time or there won't be anybody left here.
Except you would have to dedicate as much time to it as it would lock someone out. For instance, 5 bad attempts take you 0s + 1s + 2s + 4 + 8s = 15s and locks them out for the next 16s. So, if you wanted to lock someone out for a day, you have to spend a day (less one second) locking them out. Even if you automated this attack, surely IT could handle that.
One last thing: Sometimes I wonder; "Is that someone's signature? Or do they type that at the end of each post?"
It turns out that the numbnuts at PogoPlug have somehow arranged to forbid pasting userid or password into their login form. I emailed them about it and their response was that they would consider changing it as a feature enhancement. So keepass is useless there and I have to hand type my complex password. Idiots!
My "bank" (Nationwide Building Society) mails you a device which uses a debit card linked to your account, your PIN, and a specific key schedule like RSA tokens to log in and sign transactions. To log in you are provided with an 8 digit code, to sign a transaction you must provide a one-time code for the transaction generated by Nationwide and the amount paid to the device, and it returns an 8 digit signing key.
I wish I could use this when I go out shopping. It's brilliant.
Finally had enough. Come see us over at https://soylentnews.org/
The issue appears to be using a password that is one of a top N passwords.
The XKCD comic is laughably inaccurate, .e.g, in that it says that the presence or absence of capitals is one bit of entropy. Of course it is -- if you regard the first character ONLY as the candidate for capitalization.
tone
tone
...don't let people have access to the hashed passwords for your system.
From the user's perspective, it's don't use the same password in more than one place, so that if one place does let its hashed passwords loose, it can't be used against you.
paintball
My 9 character password has been busted for two years now. I now have a system that gives me 13 character passwords that are now different for each site. Unfortunately, not every account, something I've been thinking about. That seems adequate for now, my wife was bitching about how she had to go with the new system when I was trying out Win 8 Consumer Preview since I was using my Hotmail account.
Maybe using 4 "symbols" as it were, but I wouldn't limit myself to seven characters, I'm thinking about adding in a number sequence that not many people would actually know (phone number from the '60/'70s, my first work data entry machine (029 and 129 would NOT be the numbers! :), possibly the now current address of a former home that was only a RR number back then, actually, quite a few of those...), and finally adding something to identify the site to identify the account.
Of course, I always had to deal with the sites that only allowed 8 characters way back then. Some would take more, but the actual password was limited to 8. Sad actually.
Passwords are on their way to being dead. It really is only a matter of time.
I was one of the lucky 250K+ of Twitter that had to reset their passwords.
Bryan
I like how a forum, for a small community, has better password requirements than my bank does.