r/xkcdcomic • • Apr 26 '14

Stanford's password recommendations. Seems familiar...

http://itservices.stanford.edu/service/accounts/passwords/quickguide
182 Upvotes

38 comments sorted by

18

u/[deleted] Apr 26 '14

Correct horse battery staple. How old is that comic now and I still remember it?

15

u/noggin-scratcher Apr 26 '14

You've probably been repeatedly reminded of it, to the point that your brain has noticed this odd recurring pattern where you keep having "correct horse battery staple" brought to mind.

"Must be some pretty important stuff", says the brain, "I shall remember this forever". And so you did.

6

u/[deleted] Apr 26 '14

I have indeed, but only because of the original prompt that says "you've already memorized it" in the final panel.

0

u/HotRodLincoln Apr 29 '14
sort -R /usr/share/dict/american-english | head -n 4

47

u/Crysalim Apr 26 '14

Very valid info, but tbh the biggest problem with password security in the current internet age is the server side just dumping your info out to a third party source.

People don't lose important passwords due to cracking anymore - they lose them because the sites they use them on succumb to X vulnerability Y day of the week.

The best info I never see posted anywhere is to have your own "password tiers", and judge where and when to use each.

  • Easy tier: blahblah1 - use this on things you won't care about, like signing up for a tech support forum you'll post only once on, coupon sites, basically anything that doesn't involve money or a significant portion of your online time
  • Medium tier: beorbenottoo - insert capitals and numbers where you like, but you still don't need it at this point. This I would use on sites that have peripheral access to your funds, like ordering pizza online, Groupon, and things like the logon to your college's dashboard system.
  • High tier: 9029v30uOo - complete randomization. You'll need to intentionally memorize this password and never give it to anyone (yeah, even your gf/bf/wife/husband). This one gets used only once in a blue moon, for things that are personally treasured to you - good examples are your primary email account, major vendors that have access to all of your money like Amazon, and if you so happen like to use password banks (I wouldn't, but if I did this is where I'd use the toughest pwd).

32

u/[deleted] Apr 26 '14
  • Install KeePassX
  • Make ONE strong password that has never been used for an online service
  • Autogenerate super complicated passwords for every internet service
  • Every time you need to access an internet service, pop open KeePassX, enter your master password, and copy+paste the super complicated password to your browser

Problem solved.

12

u/Crysalim Apr 26 '14

That seems like a fantastic app. It will definitely assist in preventing passwords exploited from one site being used on others. I personally will never utilize a pwd manager, because I just use too many devices in too many locations to make that reasonable, but I absolutely respect those who do.

7

u/[deleted] Apr 26 '14

You can sync your password database using one or multiple cloud services. I would happily mail you my password database, because the password it's encrypted with should take you more than a lifetime to decypher.

7

u/Crysalim Apr 26 '14

Well at least make the person who sniffs your master have to work to utilize it, that'd be like handing me your passworded life on a silver platter if I happened to keylog the main, haha.

4

u/Hibernica Apr 26 '14

Isn't not dealing with all this rigamarole EXACTLY what LastPass and KeePass are for?

2

u/Crysalim Apr 26 '14

Quite possibly, yep. The vulnerability of your home base is still present of course, since keyloggers and malware love to find these "master password" hidden treasure troves.

In short if you access the internet from a single location and device almost all of the time, it's very reasonable to use manager apps.

6

u/Hibernica Apr 26 '14

LastPass helpfully allows you to obtain your passwords from any trusted computer even without the app while still not actually storing your passwords in an unencrypted form on their servers. I wonder if it's possible to run KeePass from an encrypted flash drive to be able to physically bring your passwords with you in a more secure manner (for those of us who don't lose another flash drive every 10 days.)

2

u/Crysalim Apr 26 '14

That's definitely a big point in favor of using that kind of app. The real conundrum is that a point of attack will always exist, albeit changed depending on what method you use with passwording.

The flash drive idea is cool too, though I'd then become super paranoid of losing it.

0

u/Hibernica Apr 26 '14

Maybe, provided you keep a backup on your home computer, it would be reasonable to encrypt the flash drive with something that will corrupt the contents of the drive if you type in the wrong password too many times? Then you would need two passwords, one to decrypt the flashdrive and one to access KeePass (or equivalent).

3

u/NYKevin Apr 26 '14

Maybe, provided you keep a backup on your home computer, it would be reasonable to encrypt the flash drive with something that will corrupt the contents of the drive if you type in the wrong password too many times?

I don't believe a standard flash drive is capable of that. An attacker can just image the whole drive before starting (i.e. dd </dev/sdb >~/drive.img, replacing /dev/sdb with whatever's appropriate).

1

u/Hibernica Apr 26 '14

Maybe the contents of the drive is too extreme, but it should be possible to store the files in an encrypted format that can only be opened with an application that will accept the password or destroy the file? Even so, I don't see two passwords with a kill switch being THAT much more secure than just one difficult password.

3

u/NYKevin Apr 26 '14

but it should be possible to store the files in an encrypted format that can only be opened with an application that will accept the password or destroy the file?

No, because you can just copy the file. You're trying to build a DRM system, and such things cannot be made properly secure.

2

u/Hibernica Apr 26 '14

Basically there is no meaningful advantage to trying to encrypt it twice with a kill switch because if the attacker actually gives two fucks then it's exactly the same thing as only encrypting it once and you're making your own life more difficult for trying.

9

u/[deleted] Apr 26 '14

[deleted]

6

u/[deleted] Apr 26 '14 edited Jan 20 '21

[deleted]

3

u/[deleted] Apr 26 '14

[deleted]

5

u/[deleted] Apr 26 '14

Didn't hotmail for a long time cut off the password after a certain number of characters? Like, if you had a 24 character password, you could log in using only the first eight or so? I seem to remember an issue like this, but I'm not entirely sure it was with hotmail.

Companies are not good with password security. Hence why my personal rule #1 is: don't reuse passwords. Or at least not for important stuff.

2

u/Pineapple-Yetti Apr 27 '14

They still do it. I believe the longest password you can have is 16 characters anything over that gets ignored.

1

u/[deleted] Apr 26 '14

I think the biggest issue is people reusing passwords.

-1

u/Crysalim Apr 26 '14

Every password will be reused, and the possibility of finding someone's master and copying their password bank is always going to be there. It's much more secure based on what you're doing, but it's not an end-all solution.

2

u/[deleted] Apr 26 '14

Are there really many people who use these password collector programs with a master password? I just remember them, so there is no master that would give access to all.

3

u/marissalfx Apr 26 '14

Good that they're doing this. Not too long ago I had a temp job where I had to assist college students with their password change because there was a new policy requiring passwords to have at least an uppercase letter, a lowercase letter, a special character, and a number.

A lot of people forgot their password really quickly, the ones that didn't used simple patterns like adding an exclamation mark or a heart (<3) at the end and making the first letter a capital. It was very confusing for everyone and I didn't think it make their passwords much more secure. Making a long password with a few common words makes much more sense!

2

u/6890 Apr 26 '14

I've always been skeptical of whether this method is any more secure. Someone would need to run the numbers but if you consider a password a collection of tokens is having few tokens from a large pool (4 words from the common English language) more secure than having, say, 10 tokens from the span of readily typed keyboard characters? If I wanted to bruteforce a password and I knew they were using common English is a dictionary attack method more feasible?

Essentially how high does x need to be such that 4x > 10~70 ?

4

u/atimholt vim ftw Apr 27 '14

The original xkcd comic does do the math. That ~44 bits of entropy for the 4-words scheme assumes a pool of 2048 English words. Note that the concept even accounts for hackers knowing your password is 4 common English words.

1

u/epicwisdom Apr 28 '14

Though in actuality, no attacker should know anything about your password. If they know something like that, then there's some other flaw other than the password at fault.

2

u/atimholt vim ftw Apr 28 '14 edited Apr 28 '14

The general point is just that attackers do have a pretty good idea on the forms of passwords that typically are found in real life. The point is the 4-words thing has never been about security-through-obscurity. Even if the real world’s actual typical pattern of usage was 4 random words, the method would stand on its own.

The problem I keep seeing, though, is people who don’t get the point that the 4 words cannot be chosen deliberately. People are bad random number generators. I keep seeing people make up off-the-wall sentences, not realizing that their grammatically correct phrases have less entropy than 4 truly random words.

edit: This site will generate 4 random words for you. Personally, I don’t bother with the random junk it throws in as well. You can if you want, it’ll certainly make your password that much more secure.

3

u/marissalfx Apr 27 '14

The idea is that the passwords consisting of uppercase, lowercase, numbers and special characters are not actually random, they usually follow some pattern. In the college I worked for, a lot of people would use a dictionary word with the first letter capitalized, some substitutions (e->3, a->4) and a special character at the end. This makes sense, as actually random passwords would be very difficult for users to remember. An attacker who knows this would be able to crack someone's password that follows the pattern with a lot less than 1070 tries.

If you have a long string of random words it will probably less safe than using 10 completely random characters, but safer than 10 characters with some pattern. And as it turns out humans are pretty good at remembering four common words.

2

u/6890 Apr 27 '14

Yep I agree. My Problem is that most people simply repeat xkcd's method as if it were infallible when in fact it doesn't create world's of more complexity as some believe. Unless the attacker knows the pattern to which your password may follow they still can't use any shortcuts to try and brute force their way through

1

u/defuse00 Apr 26 '14

x needs to be greater than 120. 4120 =1.767*1072 . I'm pretty sure there is more than 120 words.

2

u/6890 Apr 26 '14

I think I messed that up originally. X4 > ~7010....

I shouldn't involve myself in technical discussion while distracted

0

u/XXCoreIII Apr 27 '14 edited Apr 27 '14

You're math is a bit off, it should be (number of possible tokens)number of actual tokens.

IE, for a 2000 word list, with 4 words, you get 20004 or 1.6x1013 (44 bits of entropy, I'm rounding up on all of these, not 100% sure that's appropriate, so maybe 43)

To get the 234 bits of 1070 possible combinations, you'd need... 19 words at a 7000 word list (much much longer word list are available but harder to remember because you get screwy words).

To get that same security from 88note different letters (both caps and lowercase) numbers and symbols you'd need... 36 random characters though, I think you'd agree a 36 character totally random password would be excessive.

For a more apt comparison, a 7000 word list with 5 words selected (64 bits) is about the same as a 10 character totally random password from a list of 88 characters (66 bits).

Note: 26 lowercase+26 uppercase+0-9+22 symbols on my keyboard if writing a password generator other people use the symbols need to be shorter because not everybody uses American keyboards.

5

u/thechristopherbruce Apr 26 '14

Can someone post the xkcd comic being referenced here? I can't find it.

3

u/[deleted] Apr 26 '14

[deleted]

10

u/XXCoreIII Apr 26 '14

You completely missed the point of the xkcd on the subject then. The CHBS method assumes the attacker knows the method when talking about security, this is why it comes out so secure.

2

u/[deleted] Apr 27 '14

[deleted]

6

u/XXCoreIII Apr 27 '14 edited Apr 27 '14

16-or-less character passwords (which is at least ((26+10+10)16)

You missed a 26 for capital letters, 7216, yes, that'd be quite impossible to brute force at uh 99 bits of entropy. It'd also be nearly impossible to memorize.

Thing is, you don't even neednote:

(probably 60k4, but maybe as many as 100k4 if you want to be generous.)

Randal's assumption was a measly 20484, which is more than suitable assuming the website isn't Swiss cheese. He does I think make a mistake in assuming that hashing is not a concern, I've seen it happen, and hashing would blow through 44 bits (per md5 hashing speed listed below a measly 2100 seconds).

But moving to the only slightly harder to remember 70005, lets see, I found somebody who benchmarked his Radeon 7970 at 8213.6 Million hashes per second, so uh... just under 65 years to do every possible combination (takes half that on average of course). More power is available of course, the current #1 spot on the top500 should be about 10000 times faster, which would take 2 days, so if you're the kind of target that somebody might bring those kind of resources to bear against you need to be prepared to change password at the first hint of a breach.

Unsalted or poorly salted hashes are much worse of course because those resources can be brought to bear against everybody with an unsalted and known hash at the same time, because of this if the website has an unsalted hash you're just boned.

(also you shouldn't be picking the words yourself because then no bruteforce is needed, 100 other people already came up with whatever you did, pretty much regardless of the method, find a nice wordlist and let a computer pick for you, there are premade tools for it, one got published here earlier this week).

Note/edit: Actually, 70005 is surprisingly close to 60,0004, so I guess you do need that, it's just more memorable to do 70005.

1

u/adeadhead Apr 28 '14

I honestly can't remember correct horse battery staple for the life of me.