Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #275727 > unrolled thread

a passwordless operating system

Started by🦓 <czyborra@gmail.com>
First post2024-12-15 09:00 +0100
Last post2024-12-16 09:20 +0100
Articles 20 on this page of 68 — 23 participants

Back to article view | Back to linux.debian.user


Contents

  a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-15 09:00 +0100
    Re: a passwordless operating system debian-user@howorth.org.uk - 2024-12-15 14:50 +0100
      Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-15 15:30 +0100
      Re: a passwordless operating system songbird <songbird@anthive.com> - 2024-12-17 05:00 +0100
        Re: a passwordless operating system John Hasler <john@sugarbit.com> - 2024-12-17 05:30 +0100
          Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 06:50 +0100
            Re: Writing passwords down [was: a passwordless operating system] "Loris Bennett" <loris.bennett@fu-berlin.de> - 2024-12-17 08:30 +0100
              Re: Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 08:50 +0100
              Re: Writing passwords down [was: a passwordless operating system] Mike Castle <dalgoda+debian@gmail.com> - 2024-12-17 18:00 +0100
            Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 15:30 +0100
            Re: Writing passwords down [was: a passwordless operating system] Lee <ler762@gmail.com> - 2024-12-17 15:40 +0100
              Re: libreoffice/openoffice system theme <tomas@tuxteam.de> - 2024-12-17 16:00 +0100
            Re: Writing passwords down [was: a passwordless operating system] Michael Stone <mstone@debian.org> - 2024-12-17 17:10 +0100
              Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 18:30 +0100
                Re: Writing passwords down [was: a passwordless operating system] "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2024-12-17 18:40 +0100
              Re: Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 18:30 +0100
                Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 18:40 +0100
                  Re: Writing passwords down [was: a passwordless operating system] tomas@tuxteam.de - 2024-12-17 19:30 +0100
                    Re: Writing passwords down [was: a passwordless operating system] Nicholas Geovanis <nickgeovanis@gmail.com> - 2024-12-17 21:10 +0100
            Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-17 18:50 +0100
              Re: Writing passwords down Peter Hillier-Brook <phb@hbsys.plus.com> - 2024-12-17 20:20 +0100
                Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-17 20:50 +0100
                  Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-18 06:00 +0100
                    Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 11:00 +0100
                      Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 18:20 +0100
                        Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 19:00 +0100
                          Re: Writing passwords down "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2024-12-18 19:10 +0100
                            Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 20:10 +0100
                              Re: Writing passwords down pocket@homemail.com - 2024-12-18 21:20 +0100
                          Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 19:30 +0100
                            Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 20:30 +0100
                              Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-19 06:00 +0100
                          Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 20:30 +0100
                            Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 23:10 +0100
                        Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:20 +0100
                      Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:20 +0100
                        Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-19 02:30 +0100
                          Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:40 +0100
                          Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-19 10:20 +0100
                            Re: Writing passwords down Joe <joe@jretrading.com> - 2024-12-19 12:20 +0100
                            Re: Writing passwords down Max Nikulin <manikulin@gmail.com> - 2024-12-20 04:30 +0100
                              Re: Writing passwords down George at Clug <Clug@goproject.info> - 2024-12-20 05:40 +0100
                              Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-20 05:40 +0100
                                Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-20 06:10 +0100
                                Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-20 10:50 +0100
                                  Re: Writing passwords down George at Clug <Clug@goproject.info> - 2024-12-21 01:40 +0100
                                  Re: Writing passwords down Max Nikulin <manikulin@gmail.com> - 2024-12-21 04:30 +0100
                              Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-20 10:30 +0100
                  Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:20 +0100
                    Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-18 10:20 +0100
                      Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:30 +0100
                    Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 18:20 +0100
                      Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-18 19:00 +0100
                      Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-18 19:20 +0100
                  Re: Writing passwords down Frank Jezzer <etphonehomefrance@gmail.com> - 2024-12-22 17:30 +0100
                Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-17 23:30 +0100
              Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-17 20:30 +0100
              Re: Writing passwords down debian-user@howorth.org.uk - 2024-12-17 21:50 +0100
                Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:30 +0100
        Re: a passwordless operating system debian-user@howorth.org.uk - 2024-12-17 12:10 +0100
    Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-15 15:40 +0100
      Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 08:50 +0100
        Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-16 08:50 +0100
          Re: a passwordless operating system Andy Smith <andy@strugglers.net> - 2024-12-16 09:00 +0100
            Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:10 +0100
          Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:10 +0100
            Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-16 09:10 +0100
        Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:20 +0100

Page 2 of 4 — ← Prev page 1 [2] 3 4  Next page →


#275844 — Re: Writing passwords down

FromPeter Hillier-Brook <phb@hbsys.plus.com>
Date2024-12-17 20:20 +0100
SubjectRe: Writing passwords down
Message-ID<JULgR-hBW-3@gated-at.bofh.it>
In reply to#275841
On 17/12/2024 17:44, Michael Kjörling wrote:
> On 17 Dec 2024 06:45 +0100, from tomas@tuxteam.de:
>>> Then follow Bruce Schneier's advice and*write them down*.
>>
>> Do you have a reference?
>>
>> I ask because I'm in the middle of a discussion (and that was my advice,
>> too). Seeing what Schneier has to say on that would be very interesting.
> 
> Not Schneier, but consider also the UK National Cyber Security
> Centre's position on password managers:
> https://www.ncsc.gov.uk/blog-post/what-does-ncsc-think-password-managers
> 
> Under the heading "Should I use a password manager?" the opening is:
> "Yes. Password managers are a good thing. They give you huge
> advantages in a world where there's far too many passwords for anyone
> to remember."
> 

I couldn't cope without PasswordSafe (thanks Mr. Schneier) and the 
nonsense  about about not changing them ignores the obvious. My bank 
performs security checks by requesting a sub-set of my password. It 
doesn't take a genius to work out that after several visits the complete 
password can be deduced.

Peter HB

[toc] | [prev] | [next] | [standalone]


#275846 — Re: Writing passwords down

FromJohn Hasler <john@sugarbit.com>
Date2024-12-17 20:50 +0100
SubjectRe: Writing passwords down
Message-ID<JULJT-hN1-1@gated-at.bofh.it>
In reply to#275844
Peter Hillier-Brook writes:
> the nonsense about about not changing them ignores the obvious.

What is that?

> My bank performs security checks by requesting a sub-set of my
> password.

Sounds like a reason to find a new bank, in the meantime changing your
password after every such request.  Surely they can't be hashing the
passwords properly if that practice is of any use.
-- 
John Hasler 
john@sugarbit.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#275855 — Re: Writing passwords down

FromKaren Lewellen <klewellen@shellworld.net>
Date2024-12-18 06:00 +0100
SubjectRe: Writing passwords down
Message-ID<JUUka-pdi-1@gated-at.bofh.it>
In reply to#275846
Simply sharing a password method I was taught years ago that works well.
Granted I  never allow anything to choose a password for me, not ever.
Instead I create a sentence with aspects of the characters forming the 
password.
As an example, I will create one, not in use of course,  for the below 
sentence.
in 2012 I joined the Debian list.
Again everything above  is likely untrue, still it becomes the following.
ItlI#10t4l
I for the word in,
t is the twentieth letter of the alphabet,
l is the twelfth letter of the alphabet,
I for the word I
a # for the special character
10 for the letter   j in joined
T for the word the
4 represents the letter d in Debian, and finally
l for the word list.
Its  simply a method, but a fun one.  create a sentence that makes you 
smile to remember, finding creative representations for the letters 
numbers and needful symbols.
Yes  wise to write it down, but you can do that anywhere, with  it 
unlikely to seem like a password.
Hope that resonates,

Karen

[toc] | [prev] | [next] | [standalone]


#275865 — Re: Writing passwords down

FromMichael Kjörling <c9bc136c6063@ewoof.net>
Date2024-12-18 11:00 +0100
SubjectRe: Writing passwords down
Message-ID<JUZ0t-sAu-1@gated-at.bofh.it>
In reply to#275855
On 17 Dec 2024 23:42 -0500, from klewellen@shellworld.net (Karen Lewellen):
> Simply sharing a password method I was taught years ago that works well.
> Granted I  never allow anything to choose a password for me, not ever.
> Instead I create a sentence with aspects of the characters forming the
> password.
> As an example, I will create one, not in use of course,  for the below
> sentence.
> in 2012 I joined the Debian list.
> Again everything above  is likely untrue, still it becomes the following.
> ItlI#10t4l
> [/snip description/]

This method would seem to fail at generating randomness, because it's
based on an initial meaningful sentence (keeping in mind that natural
language has very low entropy; consider that in your example, "joined"
is much more likely in that position than, say, "aardvark", "vibrated"
or "swordsman") plus some relatively fixed, predetermined
transformations.

It also requires you to remember which sentence you used as the seed
for which service. That might work for a few services, but does it
scale into the hundreds or thousands?

Thus xkcd 936 essentially applies. https://xkcd.com/936/

As I note on https://michael.kjorling.se/password-tips/ (constructive
criticism most welcome!) "someone who has perfect knowledge of you
should not have any advantage in guessing the password".

The two main ways of meeting that criteria (which is not the only one,
but is the one which is pertinent here) is random out of a character
set, and Diceware with words selected at random. The former gives a
high degree of security for a given length, and the latter gives good
memorability. The work factor of a password or passphrase generated
using either method can be objectively quantified.

And humans in general are terrible at randomness.

-- 
Michael Kjörling
🔗 https://michael.kjorling.se

[toc] | [prev] | [next] | [standalone]


#275883 — Re: Writing passwords down

FromChris Green <cl@isbd.net>
Date2024-12-18 18:20 +0100
SubjectRe: Writing passwords down
Message-ID<JV5Sh-y4C-9@gated-at.bofh.it>
In reply to#275865
Michael Kjörling <c9bc136c6063@ewoof.net> wrote:
> 
> As I note on https://michael.kjorling.se/password-tips/ (constructive
> criticism most welcome!) "someone who has perfect knowledge of you
> should not have any advantage in guessing the password".
> 
Surely no one "has perfect knowledge of you"! :-)  I'm not even sure I
have perfect knowledge of myself, in fact I'm pretty sure I don't!

-- 
Chris Green
·

[toc] | [prev] | [next] | [standalone]


#275887 — Re: Writing passwords down

FromJohn Hasler <john@sugarbit.com>
Date2024-12-18 19:00 +0100
SubjectRe: Writing passwords down
Message-ID<JV6uZ-yph-15@gated-at.bofh.it>
In reply to#275883
Chris Green writes:
> Surely no one "has perfect knowledge of you"! :-) I'm not even sure I
> have perfect knowledge of myself, in fact I'm pretty sure I don't!

But which things about you can you be sure no one else has knowledge of?
Most people seem to think that the name of the dog they had when they
were 12 is an unguessable secret.
-- 
John Hasler 
john@sugarbit.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#275889 — Re: Writing passwords down

From"James H. H. Lampert" <jamesl@touchtonecorp.com>
Date2024-12-18 19:10 +0100
SubjectRe: Writing passwords down
Message-ID<JV6EH-yII-13@gated-at.bofh.it>
In reply to#275887
I *could* share my strategies for coming up with passwords. But then I'd 
be legally obligated to irrecoverably crash the list server, kill every 
member of the List, and kill everybody who might have seen my message in 
the List archives, or might have talked to anybody who'd read it, and 
irrecoverably crash every computer that had ever contained a copy of the 
message.

And that would be rude.

So probably better for everybody if I kept it among the tiny handful of 
secrets I'll take to my grave.

--
JHHL

[toc] | [prev] | [next] | [standalone]


#275895 — Re: Writing passwords down

FromJohn Hasler <john@sugarbit.com>
Date2024-12-18 20:10 +0100
SubjectRe: Writing passwords down
Message-ID<JV7AJ-znr-9@gated-at.bofh.it>
In reply to#275889
JHHL writes:
> I *could* share my strategies for coming up with passwords.

Mine is pwgen -s 12
-- 
John Hasler 
john@sugarbit.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#275902 — Re: Writing passwords down

Frompocket@homemail.com
Date2024-12-18 21:20 +0100
SubjectRe: Writing passwords down
Message-ID<JV8Gt-AgC-1@gated-at.bofh.it>
In reply to#275895
> Sent: Wednesday, December 18, 2024 at 2:04 PM
> From: "John Hasler" <john@sugarbit.com>
> To: debian-user@lists.debian.org
> Subject: Re: Writing passwords down
>
> JHHL writes:
> > I *could* share my strategies for coming up with passwords.
>
> Mine is pwgen -s 12

I have a better strategy for passwords
I use my wifes underwear size

[toc] | [prev] | [next] | [standalone]


#275892 — Re: Writing passwords down

FromMichael Kjörling <c9bc136c6063@ewoof.net>
Date2024-12-18 19:30 +0100
SubjectRe: Writing passwords down
Message-ID<JV6Y1-yQG-1@gated-at.bofh.it>
In reply to#275887
On 18 Dec 2024 11:57 -0600, from john@sugarbit.com (John Hasler):
>> Surely no one "has perfect knowledge of you"! :-) I'm not even sure I
>> have perfect knowledge of myself, in fact I'm pretty sure I don't!
> 
> But which things about you can you be sure no one else has knowledge of?
> Most people seem to think that the name of the dog they had when they
> were 12 is an unguessable secret.

Pretty much. Or the phone number you had at home as a child. Or your
favorite color. Or your mother's maiden name. Or that you have used
Debian since year Y. Or which year your great-grandmother died.

If I generate a Diceware passphrase - let's take one from that page as
an example, "dean unissued mystified comfort everyday chokehold" -
then I can tell you exactly how I generated it and what the inputs
were ("6 words selected at random out of the EFF English long Diceware
word list, separated by single U+0020 space characters") and this
won't really help you, because the search space is still (6^5)^6 or
about 2^77.

On the other hand, someone who knows Karen Lewellen's system for
generating a password has a fairly significant advantage over someone
who doesn't; for example, that the digit group in the middle is highly
likely to be in the range 1..26 (possibly padded to 01..26), the first
letter may or may not be capitalized, and letters other than "I" are
more likely to be lowercase than uppercase. Note that this is just
some of what can be learned from that one password and the description
of the process. And if they can guess or glean a seed sentence, or
even a part of one, then the attacker has a _huge_ advantage. On the
other hand, if someone were to learn that a Diceware passphrase begins
with "dean unissued mystified comfort", then other than perhaps that
this can help narrow down which word list was used, they have no
advantage in guessing the remainder.

-- 
Michael Kjörling
🔗 https://michael.kjorling.se

[toc] | [prev] | [next] | [standalone]


#275898 — Re: Writing passwords down

FromChris Green <cl@isbd.net>
Date2024-12-18 20:30 +0100
SubjectRe: Writing passwords down
Message-ID<JV7U5-zzp-9@gated-at.bofh.it>
In reply to#275892
Michael Kjörling <c9bc136c6063@ewoof.net> wrote:
> On 18 Dec 2024 11:57 -0600, from john@sugarbit.com (John Hasler):
> >> Surely no one "has perfect knowledge of you"! :-) I'm not even sure I
> >> have perfect knowledge of myself, in fact I'm pretty sure I don't!
> > 
> > But which things about you can you be sure no one else has knowledge of?
> > Most people seem to think that the name of the dog they had when they
> > were 12 is an unguessable secret.
> 
> Pretty much. Or the phone number you had at home as a child. Or your
> favorite color. Or your mother's maiden name. Or that you have used
> Debian since year Y. Or which year your great-grandmother died.
> 
> If I generate a Diceware passphrase - let's take one from that page as
> an example, "dean unissued mystified comfort everyday chokehold" -
> then I can tell you exactly how I generated it and what the inputs
> were ("6 words selected at random out of the EFF English long Diceware
> word list, separated by single U+0020 space characters") and this
> won't really help you, because the search space is still (6^5)^6 or
> about 2^77.
> 
But how do you remember it? It's no more memorable than a string of
numbers, in fact I find numbers easier to remember than words.

-- 
Chris Green
·

[toc] | [prev] | [next] | [standalone]


#275910 — Re: Writing passwords down

From<tomas@tuxteam.de>
Date2024-12-19 06:00 +0100
SubjectRe: Writing passwords down
Message-ID<JVgNH-LWj-1@gated-at.bofh.it>
In reply to#275898

[Multipart message — attachments visible in raw view] — view raw

On Wed, Dec 18, 2024 at 07:13:23PM +0000, Chris Green wrote:
> Michael Kjörling <c9bc136c6063@ewoof.net> wrote:

[...]

> > If I generate a Diceware passphrase - let's take one from that page as
> > an example, "dean unissued mystified comfort everyday chokehold" -

[...]

> But how do you remember it? It's no more memorable than a string of
> numbers, in fact I find numbers easier to remember than words.

But that's exactly the point. Passwords are a /personal/ thing, i.e.
something you, the person, can memorize when it becomes important.
This varies from person to person.

So use a well vetted method which works for you. If it's numbers, then
fine.

Me? I found out I can memorize well 16-places pwgen things. So my important
passwords come from there. Mostly. But this won't work for someone else.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#275897 — Re: Writing passwords down

FromChris Green <cl@isbd.net>
Date2024-12-18 20:30 +0100
SubjectRe: Writing passwords down
Message-ID<JV7U5-zzp-3@gated-at.bofh.it>
In reply to#275887
John Hasler <john@sugarbit.com> wrote:
> Chris Green writes:
> > Surely no one "has perfect knowledge of you"! :-) I'm not even sure I
> > have perfect knowledge of myself, in fact I'm pretty sure I don't!
> 
> But which things about you can you be sure no one else has knowledge of?
> Most people seem to think that the name of the dog they had when they
> were 12 is an unguessable secret.

That depends rather on how long ago they were 12 surely.  For me it's
over 60 years ago and there's very little data from back then that's
accessible.  How would you guess the name of a dog I had back in the
1950s? (If you do guess it you're wrong, I didn't have a dog)

-- 
Chris Green
·

[toc] | [prev] | [next] | [standalone]


#275904 — Re: Writing passwords down

FromJohn Hasler <john@sugarbit.com>
Date2024-12-18 23:10 +0100
SubjectRe: Writing passwords down
Message-ID<JVaoV-BVa-1@gated-at.bofh.it>
In reply to#275897
I wrote:
> But which things about you can you be sure no one else has knowledge of?
> Most people seem to think that the name of the dog they had when they
> were 12 is an unguessable secret.

Chris Green writes:
> That depends rather on how long ago they were 12 surely.

Not when the dog's name was Rover.
-- 
John Hasler 
john@sugarbit.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#275906 — Re: Writing passwords down

FromKaren Lewellen <klewellen@shellworld.net>
Date2024-12-19 02:20 +0100
SubjectRe: Writing passwords down
Message-ID<JVdmN-HAs-1@gated-at.bofh.it>
In reply to#275883

[Multipart message — attachments visible in raw view] — view raw

Have to agree.
Perfect knowledge of you seems hard to imagine in another person, let 
alone  yourself.



On Wed, 18 Dec 2024, Chris Green wrote:

> Michael Kjörling <c9bc136c6063@ewoof.net> wrote:
>>
>> As I note on https://michael.kjorling.se/password-tips/ (constructive
>> criticism most welcome!) "someone who has perfect knowledge of you
>> should not have any advantage in guessing the password".
>>
> Surely no one "has perfect knowledge of you"! :-)  I'm not even sure I
> have perfect knowledge of myself, in fact I'm pretty sure I don't!
>
> -- 
> Chris Green
> ·
>
>

[toc] | [prev] | [next] | [standalone]


#275907 — Re: Writing passwords down

FromKaren Lewellen <klewellen@shellworld.net>
Date2024-12-19 02:20 +0100
SubjectRe: Writing passwords down
Message-ID<JVdmN-HAs-3@gated-at.bofh.it>
In reply to#275865

[Multipart message — attachments visible in raw view] — view raw

Well,  I do not use hundreds.
Still that little black book is, speaking personally, far safer to my mind 
then any digital solution.



On Wed, 18 Dec 2024, Michael Kjörling wrote:

> On 17 Dec 2024 23:42 -0500, from klewellen@shellworld.net (Karen Lewellen):
>> Simply sharing a password method I was taught years ago that works well.
>> Granted I  never allow anything to choose a password for me, not ever.
>> Instead I create a sentence with aspects of the characters forming the
>> password.
>> As an example, I will create one, not in use of course,  for the below
>> sentence.
>> in 2012 I joined the Debian list.
>> Again everything above  is likely untrue, still it becomes the following.
>> ItlI#10t4l
>> [/snip description/]
>
> This method would seem to fail at generating randomness, because it's
> based on an initial meaningful sentence (keeping in mind that natural
> language has very low entropy; consider that in your example, "joined"
> is much more likely in that position than, say, "aardvark", "vibrated"
> or "swordsman") plus some relatively fixed, predetermined
> transformations.
>
> It also requires you to remember which sentence you used as the seed
> for which service. That might work for a few services, but does it
> scale into the hundreds or thousands?
>
> Thus xkcd 936 essentially applies. https://xkcd.com/936/
>
> As I note on https://michael.kjorling.se/password-tips/ (constructive
> criticism most welcome!) "someone who has perfect knowledge of you
> should not have any advantage in guessing the password".
>
> The two main ways of meeting that criteria (which is not the only one,
> but is the one which is pertinent here) is random out of a character
> set, and Diceware with words selected at random. The former gives a
> high degree of security for a given length, and the latter gives good
> memorability. The work factor of a password or passphrase generated
> using either method can be objectively quantified.
>
> And humans in general are terrible at randomness.
>
> -- 
> Michael Kjörling
> 🔗 https://michael.kjorling.se
>
>

[toc] | [prev] | [next] | [standalone]


#275908 — Re: Writing passwords down

FromJohn Hasler <john@sugarbit.com>
Date2024-12-19 02:30 +0100
SubjectRe: Writing passwords down
Message-ID<JVdwt-HQb-7@gated-at.bofh.it>
In reply to#275907
Karen writes:
> Well, I do not use hundreds.  Still that little black book is,
> speaking personally, far safer to my mind then any digital solution.

If you are going to use a little black book why not just use random
passwords?  pwgen -s 10 and write it down.

And if they insist on a "password recovery secret" give them a random
string for that as well.
-- 
John Hasler 
john@sugarbit.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#275909 — Re: Writing passwords down

FromKaren Lewellen <klewellen@shellworld.net>
Date2024-12-19 02:40 +0100
SubjectRe: Writing passwords down
Message-ID<JVdGa-I7F-9@gated-at.bofh.it>
In reply to#275908
because my little black book is accessible for me.
random passwords that I cannot recall are not for me personally.
Additionally, most password managers are unlikely to work with my setup.
But that is me.



On Wed, 18 Dec 2024, John Hasler wrote:

> Karen writes:
>> Well, I do not use hundreds.  Still that little black book is,
>> speaking personally, far safer to my mind then any digital solution.
>
> If you are going to use a little black book why not just use random
> passwords?  pwgen -s 10 and write it down.
>
> And if they insist on a "password recovery secret" give them a random
> string for that as well.
> -- 
> John Hasler
> john@sugarbit.com
> Elmwood, WI USA
>
>

[toc] | [prev] | [next] | [standalone]


#275911 — Re: Writing passwords down

FromChris Green <cl@isbd.net>
Date2024-12-19 10:20 +0100
SubjectRe: Writing passwords down
Message-ID<JVkRj-QJ1-5@gated-at.bofh.it>
In reply to#275908
John Hasler <john@sugarbit.com> wrote:
> Karen writes:
> > Well, I do not use hundreds.  Still that little black book is,
> > speaking personally, far safer to my mind then any digital solution.
> 
> If you are going to use a little black book why not just use random
> passwords?  pwgen -s 10 and write it down.
> 
Because a long series of random characters is incredibly difficult to
type accurately!

Horses for courses, I enter login passwords/passphrases quite frequently (lots of
different systems that I ssh to) long, unmemorable, passwords would be
useless.

For the odd password that needs to be **extra** secure I suppose I
could use a written down password.

-- 
Chris Green
·

[toc] | [prev] | [next] | [standalone]


#275912 — Re: Writing passwords down

FromJoe <joe@jretrading.com>
Date2024-12-19 12:20 +0100
SubjectRe: Writing passwords down
Message-ID<JVmJr-RUr-15@gated-at.bofh.it>
In reply to#275911
On Thu, 19 Dec 2024 08:56:00 +0000
Chris Green <cl@isbd.net> wrote:

> John Hasler <john@sugarbit.com> wrote:
> > Karen writes:  
> > > Well, I do not use hundreds.  Still that little black book is,
> > > speaking personally, far safer to my mind then any digital
> > > solution.  
> > 
> > If you are going to use a little black book why not just use random
> > passwords?  pwgen -s 10 and write it down.
> >   
> Because a long series of random characters is incredibly difficult to
> type accurately!
> 
> Horses for courses, I enter login passwords/passphrases quite
> frequently (lots of different systems that I ssh to) long,
> unmemorable, passwords would be useless.
> 
> For the odd password that needs to be **extra** secure I suppose I
> could use a written down password.
> 

Something nobody has mentioned in connection with remembering passwords
is how often they are used. Many passwords I use are created and then
not used for another year or more. There's no way to remember anything
of any complexity at all over that period with no refreshing, whereas
even quite a random and complicated one will start to stick if used
every day.

-- 
Joe

[toc] | [prev] | [next] | [standalone]


Page 2 of 4 — ← Prev page 1 [2] 3 4  Next page →

Back to top | Article view | linux.debian.user


csiph-web