• Security incident: ISF was recently accessed by intruders. Please change your password, and change it anywhere else you used it. Read more

Password rules stupid

Why isn't that realistic? IIRC password files get compromised all the time.


Because if your password is compromised like that, like someone can brute force it like that, we don't even have to begin to discuss. rjh01 advising us to take complexity out of our passwords isn't even wrong.

Use upper case and lower case and numbers and special characters. The bigger the amount of characters is, the safer your password will be. Obviously.
 
Last edited:
Password complexity is sooo last year
It's all about 14+ character passphrases and MFA

I find "You're my Wonderall" far easier to remember and type than "F1shguts!"
 
Because if your password is compromised like that, like someone can brute force it like that, we don't even have to begin to discuss. rjh01 advising us to take complexity out of our passwords isn't even wrong.

Use upper case and lower case and numbers and special characters. The bigger the amount of characters is, the safer your password will be. Obviously.

Obviously? With a brute force attack the computer does not know about "upper case and lower case and numbers and special characters". It just tries all the 8-bit numbers at each positions.
 
Obviously? With a brute force attack the computer does not know about "upper case and lower case and numbers and special characters". It just tries all the 8-bit numbers at each positions.


Well, maybe. A lot do use a limited character space to save time. If you know what letters, numbers, and special characters are allowed it’s much quicker to just search those than the entire ASCII space (no one allows those various border characters in passwords, for example).

But yeah, it’s only a difference of making it harder by increasing the possibilities per space vs increasing the number of spaces.

It’s comparable to dice. If you’re trying to prevent a person from rolling all one’s, you can either:

Use a did with more sides (like a d20 or d12), comparable to adding upper/lower/numbers/etc

Or

Add more dice (harder to roll all ones on 3 dice than on one), comparable to increasing password length.

ETA: I’ve also heard some people advocating for opening up a larger character space and allowing emojis in passwords. That might have some utility.

Sent from my volcanic island lair using carrier pigeon.
 
Last edited:
The actual example password is "correcthorsebatterystaple". I just didn't feel like going back and clearing the spaces. But even "correct horse battery staple" isn't in any dictionary of common words. You're not asking the computer to guess four common words in order. You're asking the computer to guess a single 14-character string.

Just "it's a string" and has X characters isn't telling the whole story. What matters is really how many bits of information are in there. Otherwise they wouldn't bother telling you to also use numbers, punctuation, signs and upper/lower-case.

For example the same 14 digit string has 84 bits of information, i.e., it's one in 284 or approx 2*1025 if it's truly random from any of the characters that can be in Base 64. It's only 2614 or approx 6.5*1019 if it's only lowercase letters like the kind of words you and XKCD seem to propose. That alone cut down the effort to crack it by a factor of literally 300,000.

If you know it must be splittable into full correct words from the dictionary, that's cutting down the number of possible combinations even more dramatically.


"Ah," will some intellectual proletar interject right about now, "but you don't really KNOW it. Someone might not be following that advice."

Well, good for them, because that person is smart. But if enough people start following the XKCD advice -- or using phrases from songs, same idea -- it becomes a matter of bang per buck. Meaning probabilities.

Let's say only 10% of people start following xkcd's advice. So now you have this small subspace of possible passwords that meet that criterion, but can collide with 10% of the passwords, or the orders-of-magnitude bigger space of possible combinations that can get a collision with the other 90% of the passwords. Of course you'll try the xkcd ones first, because they offer an insanely higher return on investment. As in, probability to get a hit per computing cycle.
 
When asked to choose a password, could they please tell me the password rules before I infringe them?
 
Obviously? With a brute force attack the computer does not know about "upper case and lower case and numbers and special characters". It just tries all the 8-bit numbers at each positions.

A brute force attack is only as dumb as you program it to be. There's nothing to stop you from trying stuff like only combinations of dictionary words, only the first letter capitalized, and only 1 or 2 standard numeric substitutions (like 3 instead of E, zero instead of O, etc) for each of them. Or whatever else you think is promising a better return on investment for your CPU or GPU cycles.

Yes, you'll miss some people's passwords, but increase your chance of finding someone else's in a finite time.
 
A brute force attack is only as dumb as you program it to be. There's nothing to stop you from trying stuff like only combinations of dictionary words, only the first letter capitalized, and only 1 or 2 standard numeric substitutions (like 3 instead of E, zero instead of O, etc) for each of them. Or whatever else you think is promising a better return on investment for your CPU or GPU cycles.

Yes, you'll miss some people's passwords, but increase your chance of finding someone else's in a finite time.


This. As mentioned before, the common trope of trying to hack into an individual account is not really accurate. Most often, you have a hash file or just a list of valid usernames. You aren’t trying to crack one in particular, you’re looking for the one user that has a weak or common password.

It’s a LOT easier to crack a low security account then later escalate privilege than to try and crack a high-privilege account from the get-go (besides those cases where people forget to remove vilify-in default accounts, that is).


Sent from my volcanic island lair using carrier pigeon.
 
I assume most halfway competent password cracking problems don't just randomly guess but have algorithms or hell if nothing else lists of common passwords to try first.

Even if you know you are going to wind up brute forcing something there's nothing lost in trying the obvious answers first.
 
I assume most halfway competent password cracking problems don't just randomly guess but have algorithms or hell if nothing else lists of common passwords to try first.

Even if you know you are going to wind up brute forcing something there's nothing lost in trying the obvious answers first.


Yeah. Brute forcing you most often see if someone has a hash file, cause that gives them the time and attempts to make it work.

Dictionary attacks are the ones that use a dictionary of common passwords, and they usually try a wide range of user accounts to avoid lockout timers: I.e. start with asmith, then bjones, then cWalters, etc…by the time it gets back to asmith the timer between failed entries is likely to reset.

The days of the artisan are over; modern cracking is almost exclusively mass production :)


Sent from my volcanic island lair using carrier pigeon.
 

ISF - Join now!

Every member here is approved by hand. No bots, no spam, just people who care about evidence and honest debate.

Membership is free!

Create your free account

Back
Top Bottom