Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #185717 > unrolled thread
| Started by | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| First post | 2017-08-22 17:10 +0200 |
| Last post | 2017-09-04 01:10 +0200 |
| Articles | 20 on this page of 117 — 22 participants |
Back to article view | Back to linux.debian.user
One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-22 17:10 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-22 21:50 +0200
Re: One-line password generator <tomas@tuxteam.de> - 2017-08-22 22:10 +0200
Re: One-line password generator John Hasler <jhasler@newsguy.com> - 2017-08-22 22:50 +0200
Re: One-line password generator Jude DaShiell <jdashiel@panix.com> - 2017-08-23 14:40 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-22 22:20 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-22 22:20 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-22 22:30 +0200
Re: One-line password generator Glenn English <ghe2001@gmail.com> - 2017-08-23 22:40 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-23 00:40 +0200
Re: One-line password generator Lck Ras <likcoras@riseup.net> - 2017-08-23 02:30 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-23 19:20 +0200
Re: One-line password generator Lck Ras <likcoras@riseup.net> - 2017-08-24 03:00 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-23 17:20 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-23 19:00 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-23 20:00 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-23 21:20 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-24 01:10 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-24 19:50 +0200
Re: One-line password generator David Wright <deblis@lionunicorn.co.uk> - 2017-08-25 03:00 +0200
Re: One-line password generator Curt <curty@free.fr> - 2017-08-25 10:50 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-25 11:30 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-25 15:40 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-25 16:50 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-25 18:10 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-25 19:20 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-25 20:10 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-25 20:50 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-25 21:00 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-25 19:00 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-25 19:00 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-25 19:20 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-25 20:20 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-25 19:20 +0200
Re: One-line password generator Jape Person <japers@comcast.net> - 2017-08-22 22:20 +0200
Re: One-line password generator Jude DaShiell <jdashiel@panix.com> - 2017-08-23 14:40 +0200
Re: One-line password generator Mike McClain <mike.junk.46@att.net> - 2017-08-23 03:10 +0200
Re: One-line password generator Teemu Likonen <tlikonen@iki.fi> - 2017-08-23 06:10 +0200
Re: One-line password generator Aaron Toponce <aaron.toponce@gmail.com> - 2017-08-23 21:20 +0200
Re: One-line password generator Greg Wooledge <wooledg@eeg.ccf.org> - 2017-08-23 21:30 +0200
Re: One-line password generator Aaron Toponce <aaron.toponce@gmail.com> - 2017-08-23 21:40 +0200
Re: One-line password generator Fungi4All <fungilife@protonmail.com> - 2017-08-23 22:50 +0200
Re: One-line password generator Terence <terence.john@gmail.com> - 2017-08-23 23:40 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-26 20:30 +0200
Re: One-line password generator Nicolas George <george@nsup.org> - 2017-08-26 20:40 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-26 21:10 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-27 16:00 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-26 21:20 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-27 16:00 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-27 17:10 +0200
Re: One-line password generator Curt <curty@free.fr> - 2017-08-27 20:10 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-27 20:10 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-27 21:10 +0200
Re: One-line password generator Andy Smith <andy@strugglers.net> - 2017-08-28 00:00 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-28 09:40 +0200
Re: One-line password generator Curt <curty@free.fr> - 2017-08-28 11:40 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-28 12:10 +0200
Re: One-line password generator Andy Smith <andy@strugglers.net> - 2017-08-28 13:50 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-28 15:20 +0200
Re: One-line password generator Zenaan Harkness <zenaan@freedbms.net> - 2017-08-29 04:40 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-29 09:10 +0200
Re: One-line password generator Zenaan Harkness <zenaan@freedbms.net> - 2017-08-29 10:50 +0200
Re: One-line password generator Zenaan Harkness <zenaan@freedbms.net> - 2017-08-29 11:00 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-29 12:50 +0200
Re: One-line password generator Zenaan Harkness <zenaan@freedbms.net> - 2017-08-29 13:00 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-29 14:30 +0200
Re: One-line password generator Zenaan Harkness <zenaan@freedbms.net> - 2017-08-30 03:50 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-30 12:40 +0200
Re: One-line password generator Andy Smith <andy@strugglers.net> - 2017-08-29 14:10 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-29 15:00 +0200
Re: One-line password generator Zenaan Harkness <zenaan@freedbms.net> - 2017-08-30 03:50 +0200
Re: One-line password generator Greg Wooledge <wooledg@eeg.ccf.org> - 2017-08-30 14:20 +0200
Re: One-line password generator Gene Heskett <gheskett@shentel.net> - 2017-08-30 14:50 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-30 15:20 +0200
Re: One-line password generator Gene Heskett <gheskett@shentel.net> - 2017-08-30 15:30 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-30 15:50 +0200
Re: One-line password generator Gene Heskett <gheskett@shentel.net> - 2017-08-30 16:00 +0200
Re: One-line password generator Greg Wooledge <wooledg@eeg.ccf.org> - 2017-08-30 16:10 +0200
Re: One-line password generator Gene Heskett <gheskett@shentel.net> - 2017-08-30 18:50 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-30 16:30 +0200
Re: One-line password generator Gene Heskett <gheskett@shentel.net> - 2017-08-30 20:10 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-30 23:00 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-09-01 10:40 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-09-01 10:50 +0200
Re: One-line password generator Curt <curty@free.fr> - 2017-08-30 16:30 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-30 17:00 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-30 20:00 +0200
Re: One-line password generator Zenaan Harkness <zenaan@freedbms.net> - 2017-08-29 11:00 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-27 21:20 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-29 21:20 +0200
Re: One-line password generator Reco <recoverym4n@gmail.com> - 2017-08-29 21:40 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-29 22:00 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-29 23:00 +0200
Re: One-line password generator Curt <curty@free.fr> - 2017-08-30 10:50 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-30 12:40 +0200
Re: One-line password generator Reco <recoverym4n@gmail.com> - 2017-08-30 00:00 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-31 21:10 +0200
Re: One-line password generator Fungi4All <fungilife@protonmail.com> - 2017-08-31 21:20 +0200
Re: One-line password generator Reco <recoverym4n@gmail.com> - 2017-08-31 21:40 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-27 04:20 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-08-27 16:00 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-27 16:40 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-09-01 17:00 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-09-01 21:50 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-09-01 23:50 +0200
Re: One-line password generator Jude DaShiell <jdashiel@panix.com> - 2017-09-02 11:50 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-09-02 13:00 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-09-02 19:20 +0200
Re: One-line password generator Jude DaShiell <jdashiel@panix.com> - 2017-09-02 20:30 +0200
Re: One-line password generator "Thomas Schmitt" <scdbackup@gmx.net> - 2017-09-02 21:00 +0200
Re: One-line password generator Brian <ad44@cityscape.co.uk> - 2017-09-02 22:00 +0200
Re: One-line password generator Zenaan Harkness <zenaan@freedbms.net> - 2017-09-02 01:50 +0200
Re: One-line password generator Zenaan Harkness <zenaan@freedbms.net> - 2017-09-02 01:50 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-09-02 04:40 +0200
Re: One-line password generator Zenaan Harkness <zenaan@freedbms.net> - 2017-09-02 05:40 +0200
Re: One-line password generator Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-09-02 16:40 +0200
Re: One-line password generator Zenaan Harkness <zenaan@freedbms.net> - 2017-09-04 01:10 +0200
Page 1 of 6 [1] 2 3 4 5 6 Next page →
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-22 17:10 +0200 |
| Subject | One-line password generator |
| Message-ID | <uhiYz-45R-39@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
I have the following line in my Bash init file: “alias gen-password="head -c 16 /dev/urandom | base64 | head -c 22 && echo"” This generates a password with just above 128 bits of entropy. You may find it useful. -- Do not eat animals, respect them as you respect people. https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan
[toc] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2017-08-22 21:50 +0200 |
| Message-ID | <uhnlx-6Ud-19@gated-at.bofh.it> |
| In reply to | #185717 |
On Tue 22 Aug 2017 at 10:04:59 -0500, Mario Castelán Castro wrote: > I have the following line in my Bash init file: > > “alias gen-password="head -c 16 /dev/urandom | base64 | head -c 22 && echo"” > > This generates a password with just above 128 bits of entropy. You may > find it useful. Wow! Can you suggest something which gives one teensy-weensy bit of memorability? -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2017-08-22 22:10 +0200 |
| Message-ID | <uhnES-7gO-17@gated-at.bofh.it> |
| In reply to | #185740 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Tue, Aug 22, 2017 at 08:46:24PM +0100, Brian wrote: > On Tue 22 Aug 2017 at 10:04:59 -0500, Mario Castelán Castro wrote: > > > I have the following line in my Bash init file: > > > > “alias gen-password="head -c 16 /dev/urandom | base64 | head -c 22 && echo"” > > > > This generates a password with just above 128 bits of entropy. You may > > find it useful. > > Wow! Can you suggest something which gives one teensy-weensy bit of > memorability? Personally I use pwgen, but one has to admit that the OP's solution is elegant. And memorability is... in the eye of the beholder (and it has more entropy per char as default pwgen, so...) Cheers - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlmcjhwACgkQBcgs9XrR2kYsQgCfeR1yyBAUbZdIk6QJK2DNqlat rLcAnAm7m08X6v36ziGyLVWc0HuPWnvw =OOfH -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <jhasler@newsguy.com> |
|---|---|
| Date | 2017-08-22 22:50 +0200 |
| Message-ID | <uhohA-7x1-33@gated-at.bofh.it> |
| In reply to | #185741 |
Brian writes: > Wow! Can you suggest something which gives one teensy-weensy bit of > memorability? Follow Bruce Schneier's advice and write your passwords down. -- John Hasler jhasler@newsguy.com Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | Jude DaShiell <jdashiel@panix.com> |
|---|---|
| Date | 2017-08-23 14:40 +0200 |
| Message-ID | <uhD6W-x6-15@gated-at.bofh.it> |
| In reply to | #185747 |
It's a good idea to write passwords down in reverse too. Just remember you did that though. If someone entered a password completely backward because they got your writing it would maybe be interesting to have an automated email message or text sent to the computer owner or alternatively simply have the computer automatically disconnect from the internet then shut down. I don't know if any of these security responses are possible with Linux yet. Bricking passwords would also be useful for cell phones and tablets but not for those trying to invade your privacy. On Tue, 22 Aug 2017, John Hasler wrote: > Date: Tue, 22 Aug 2017 16:42:40 > From: John Hasler <jhasler@newsguy.com> > To: debian-user@lists.debian.org > Subject: Re: One-line password generator > Resent-Date: Tue, 22 Aug 2017 20:43:06 +0000 (UTC) > Resent-From: debian-user@lists.debian.org > > Brian writes: >> Wow! Can you suggest something which gives one teensy-weensy bit of >> memorability? > > Follow Bruce Schneier's advice and write your passwords down. > --
[toc] | [prev] | [next] | [standalone]
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-22 22:20 +0200 |
| Message-ID | <uhnOx-7kH-11@gated-at.bofh.it> |
| In reply to | #185740 |
[Multipart message — attachments visible in raw view] — view raw
On 22/08/17 14:46, Brian wrote: > Wow! Can you suggest something which gives one teensy-weensy bit of > memorability? I do not recommend “memorable passwords” at all. The reasons are as explained next. If the password is not important (for example, account of web forums) then you can use store it in a plain text file or a password manager. Firefox has a built-in password manager which works fine. Here memorability does not matter at all, as you just have to copy and paste, or let the password manager fill it automatically. Anyway, one could not memorize enough passwords for all the things that require one (esp. web sites). If the password is important, then for a reasonable amount of entropy, a memorable password will be too long and VERY slow to input. I suggest the following approach: Generate a 3-bit long password, for example: mario@svetlana [0] [/home/mario] $ head -c 3 /dev/urandom | base64 w5eJ Write it in a paper or leave it in the terminal. Invent a mnemonic for it or just memorize as is. In this case, I can think of “_W_ill has _5_ fingers in _each_ _J_and (hand spelled wrong)”. Several times through the day, try to remember the password and *then* look at the paper or terminal to check. Allow yourself 1 day to memorize it, then if you used a paper, either *eat it* or chew it until it is an homogeneous blob and then spit it. Repeat this for several days. Your password at the end is the *concatenation* of all these 4-character chunks in the order generated. If at some point you get a chunk that is hard to memorize, you can discard it and try again. Discarding removes some entropy but I do not think it is significant (as a *rule of thumb*: You can choose the “best” of 4 tries for any block and lose only 2 bits of entropy; if you do this each block, then you still have 88 bits of entropy). To assure that each chunk gives the maximum amount of entropy (24 bits) you must commit yourself to use whatever is generated, that is, without discarding. Each chunk gives 24 bits of entropy. I recommend to use a 4-chunck long password, for 96 bits of entropy. In my opinion, there is no point in a longer password; the attacker would simply kidnap you and give you amobarbital instead of trying brute force. 5 chunks give 120 bits, which is IMO is enough for *any* password that can be trusted to a single person. For stronger security requirements, one should instead require N of M good passwords to unlock the ICBM and then distribute the individual passwords as appropriate. Regards. -- Do not eat animals, respect them as you respect people. https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan
[toc] | [prev] | [next] | [standalone]
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-22 22:20 +0200 |
| Message-ID | <uhnOx-7kH-9@gated-at.bofh.it> |
| In reply to | #185742 |
[Multipart message — attachments visible in raw view] — view raw
On 22/08/17 15:14, Mario Castelán Castro wrote: > Generate a 3-bit long password, for example: > > mario@svetlana [0] [/home/mario] > $ head -c 3 /dev/urandom | base64 > w5eJ Apologies. This is of course, a 3 BYTE long password (24 bits), not 3 BIT long. Hehe. -- Do not eat animals, respect them as you respect people. https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan
[toc] | [prev] | [next] | [standalone]
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-22 22:30 +0200 |
| Message-ID | <uhnYg-7oI-47@gated-at.bofh.it> |
| In reply to | #185742 |
[Multipart message — attachments visible in raw view] — view raw
On 22/08/17 15:14, Mario Castelán Castro wrote: > Generate a 3-bit long password, for example: > > mario@svetlana [0] [/home/mario] > $ head -c 3 /dev/urandom | base64 > w5eJ Apologies. This is of course, a 3 BYTE long password (24 bits), not 3 BIT long!! I also want to point that by default, if the input to base64 is not an input of 3 bytes then the last digit does not have full entropy. The one-liner that I gave in my *original* message is processed to have full entropy in *all* digits (hence the double use of “head” command), for a total of 132 bits. The line quoted here does not need this processing because the input gives exactly enough entropy to generate 4 characters with full entropy. -- Do not eat animals, respect them as you respect people. https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan
[toc] | [prev] | [next] | [standalone]
| From | Glenn English <ghe2001@gmail.com> |
|---|---|
| Date | 2017-08-23 22:40 +0200 |
| Message-ID | <uhKBt-5gf-27@gated-at.bofh.it> |
| In reply to | #185746 |
On Tue, Aug 22, 2017 at 8:20 PM, Mario Castelán Castro <marioxcc.MT@yandex.com> wrote: I ask the user for a fairly long line in a song, or maybe a poem, that they know or can learn. Something like the third line of a 19th century translation of Homer's Odyssey. I use the first letter, randomly upper-cased if necessary, of the words and the punctuation for the password. Maybe hang a couple memorable digits on the end. It's gibberish, but memorable, and not susceptible to a dictionary attack. The best I've seen so far is a couple lines from Mozart's opera "Don Giovanni", from well inside the aria "La ci darem la mano" -- in Italian. -- Glenn English
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2017-08-23 00:40 +0200 |
| Message-ID | <uhq02-hY-35@gated-at.bofh.it> |
| In reply to | #185742 |
On Tue 22 Aug 2017 at 15:14:37 -0500, Mario Castelán Castro wrote: > On 22/08/17 14:46, Brian wrote: > > Wow! Can you suggest something which gives one teensy-weensy bit of > > memorability? > > I do not recommend “memorable passwords” at all. The reasons are as > explained next. You can recommend what you want but give me IhaveaMemorablePasswordwhichIwillnotforget! as opposed to WVAq7XLM4va6e1A4Bb4+Zw You will now explain why the first one will be broken in the next 100 years. I'm past caring after that. > If the password is not important (for example, account of web forums) > then you can use store it in a plain text file or a password manager. > Firefox has a built-in password manager which works fine. Here > memorability does not matter at all, as you just have to copy and paste, > or let the password manager fill it automatically. Anyway, one could not > memorize enough passwords for all the things that require one (esp. web > sites). You are digressing. Every password is important. Basing a password on the perceived imortance of an account is unwise. What Firefox has is of no great consequence when it comes to memorability. For one of my web forums: M92FGisthepostcodeformyhomeaddress A weak password? > If the password is important, then for a reasonable amount of entropy, a > memorable password will be too long and VERY slow to input. I suggest > the following approach: Stick entropy. It is highly unlikely that a password is broken because it is not in the 128-bit entropy category. > Generate a 3-bit long password, for example: > > mario@svetlana [0] [/home/mario] > $ head -c 3 /dev/urandom | base64 > w5eJ > > Write it in a paper or leave it in the terminal. Invent a mnemonic for > it or just memorize as is. In this case, I can think of “_W_ill has _5_ > fingers in _each_ _J_and (hand spelled wrong)”. Fine. But where is the improvement over Willhas5fingerson_each_Jand as a password? A bit longer to type, perhaps, but not spectacularly so. -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | Lck Ras <likcoras@riseup.net> |
|---|---|
| Date | 2017-08-23 02:30 +0200 |
| Message-ID | <uhrIu-1Ej-11@gated-at.bofh.it> |
| In reply to | #185757 |
On 08/23/2017 07:31 AM, Brian wrote: > On Tue 22 Aug 2017 at 15:14:37 -0500, Mario Castelán Castro wrote: > You can recommend what you want but give me > > IhaveaMemorablePasswordwhichIwillnotforget! > > as opposed to > > WVAq7XLM4va6e1A4Bb4+Zw > > You will now explain why the first one will be broken in the next > 100 years. I'm past caring after that. The problem with that kind of password generation is that it leaks in unexpected ways, and it can be hard to understand how much it matters. When you know nothing about a password, it can be quite hard to guess, but as you reveal more information about it and its construction (max length, character set, format, etc.) it becomes easier and easier. With randomly generated passwords, you still have an easy-to-understand "hard limit" on how easy it will be to guess, unless you start leaking individual characters of it, even if you reveal how the password is constructed. In the other hand, with passwords like the ones you described, it can be quite difficult to gauge how hard it is to guess, and how much you can reveal about it before it being unsafe. Eg. knowing that you create your passwords like that can make it significantly easier for someone else to guess your password, which could potentially be dangerous, especially if done by someone who knows you well. I personally use diceware, which is relatively memorable and secure enough. Revealing the fact that I use diceware makes guessing my passwords significantly easier, but it still is very far in the "impossible" territory. I don't think leaving your passwords up to chance is a good idea. You should know, not guess, whether it is safe or not.
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2017-08-23 19:20 +0200 |
| Message-ID | <uhHtT-3mE-7@gated-at.bofh.it> |
| In reply to | #185760 |
On Wed 23 Aug 2017 at 09:11:15 +0900, Lck Ras wrote: > On 08/23/2017 07:31 AM, Brian wrote: > > On Tue 22 Aug 2017 at 15:14:37 -0500, Mario Castelán Castro wrote: > > You can recommend what you want but give me > > > > IhaveaMemorablePasswordwhichIwillnotforget! > > > > as opposed to > > > > WVAq7XLM4va6e1A4Bb4+Zw > > > > You will now explain why the first one will be broken in the next > > 100 years. I'm past caring after that. > > The problem with that kind of password generation is that it leaks in > unexpected ways, and it can be hard to understand how much it matters. > > When you know nothing about a password, it can be quite hard to guess, > but as you reveal more information about it and its construction (max > length, character set, format, etc.) it becomes easier and easier. > > With randomly generated passwords, you still have an easy-to-understand > "hard limit" on how easy it will be to guess, unless you start leaking > individual characters of it, even if you reveal how the password is > constructed. > > In the other hand, with passwords like the ones you described, it can be > quite difficult to gauge how hard it is to guess, and how much you can > reveal about it before it being unsafe. You should never reveal how your passwords are generated. In detail, that is; in principle there might be no harm done. > Eg. knowing that you create your passwords like that can make it > significantly easier for someone else to guess your password, which > could potentially be dangerous, especially if done by someone who knows > you well. Agreed. Account passwords being guessed can surely only happen when the account owner is known to the perpetrator. > I personally use diceware, which is relatively memorable and secure > enough. Revealing the fact that I use diceware makes guessing my > passwords significantly easier, but it still is very far in the > "impossible" territory. > > I don't think leaving your passwords up to chance is a good idea. You > should know, not guess, whether it is safe or not. How does one know MyDogHasNoNose.HowDoesItSmell?Terrible! (old jokes are vey memorable) is a safe password? -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | Lck Ras <likcoras@riseup.net> |
|---|---|
| Date | 2017-08-24 03:00 +0200 |
| Message-ID | <uhOF3-7Ik-7@gated-at.bofh.it> |
| In reply to | #185783 |
On 08/24/2017 02:11 AM, Brian wrote: > You should never reveal how your passwords are generated. In detail, > that is; in principle there might be no harm done. But how do you know how much you can reveal about it until there is real harm done? You can't really know for sure how much entropy your password has, unlike a randomly generated password, where it is significantly easier to estimate. Revealing as much as "my passwords are 30 random alphanumeric characters" will be fine in that case, but there is no such measure with passwords like the ones you have described. >> Eg. knowing that you create your passwords like that can make it >> significantly easier for someone else to guess your password, which >> could potentially be dangerous, especially if done by someone who knows >> you well. > > Agreed. Account passwords being guessed can surely only happen when the > account owner is known to the perpetrator. Sure, but the problem is that the account owner may not even be aware that this is happening. For example, with human-generated passwords, telling a joke, talking about your mother's maiden name, or talking about your favorite band may be leaking information about your passwords, and it is really hard to understand how much(or how little) damage it has done. With passwords, you should be sure, not guess, that you are safe. > How does one know > > MyDogHasNoNose.HowDoesItSmell?Terrible! > > (old jokes are vey memorable) is a safe password? You don't, and that's the problem, I believe.
[toc] | [prev] | [next] | [standalone]
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-23 17:20 +0200 |
| Message-ID | <uhFBL-2c7-1@gated-at.bofh.it> |
| In reply to | #185757 |
[Multipart message — attachments visible in raw view] — view raw
On 22/08/17 17:31, Brian wrote: > You will now explain why the first one will be broken in the next > 100 years. I'm past caring after that. If you do not care about security, you could generate a single 4 character bit block with my method and save typing. >> If the password is not important (for example, account of web forums) >> then you can use store it in a plain text file or a password manager. >> Firefox has a built-in password manager which works fine. Here >> memorability does not matter at all, as you just have to copy and paste, >> or let the password manager fill it automatically. Anyway, one could not >> memorize enough passwords for all the things that require one (esp. web >> sites). > > You are digressing. Every password is important. Basing a password on > the perceived imortance of an account is unwise. What Firefox has is of > no great consequence when it comes to memorability. No, I am not digressing. Not every password is equally important. How important is the password you use to post in a forum that you will not visit again? Is it as important as the password of your GNU PG private key? > Fine. But where is the improvement over > > Willhas5fingerson_each_Jand > > as a password? A bit longer to type, perhaps, but not spectacularly so. This is just for a block of 24 bits, thus this is a rough equivalent of 4 characters under my method, which is *much* shorter to type. Assuming your mnemonic function is one-to-one (which it is not) you would need 4 such to achieve the 96 bits of entropy that I recommend. Then the difference in length is very significant. Moreover, since you are suggesting using the mnemonic itself, and the mnemonic function is not well defined, the entropy is not well defined either. ----- Anyway, I posted this suggestion for those who want a provably (not “probably”) secure password (up to a certain entropy). I know not everybody will like my method, and that is fine for me. -- Do not eat animals, respect them as you respect people. https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2017-08-23 19:00 +0200 |
| Message-ID | <uhHay-30H-13@gated-at.bofh.it> |
| In reply to | #185779 |
On Wed 23 Aug 2017 at 10:13:01 -0500, Mario Castelán Castro wrote: > On 22/08/17 17:31, Brian wrote: > > You will now explain why the first one will be broken in the next > > 100 years. I'm past caring after that. > > If you do not care about security, you could generate a single 4 > character bit block with my method and save typing. One online password checker (not that I understand how it works or even trust it) gives IhaveaMemorablePasswordwhichIwillnotforget! 211.6 bits of entropy and rates it as "very strong" and "overkill". I'd place any discomfort with having to type a long password low down on my list password formation difficulties. Long, with some complexity and memorable goes a long way to securing accounts on a computer or on the web. > >> If the password is not important (for example, account of web forums) > >> then you can use store it in a plain text file or a password manager. > >> Firefox has a built-in password manager which works fine. Here > >> memorability does not matter at all, as you just have to copy and paste, > >> or let the password manager fill it automatically. Anyway, one could not > >> memorize enough passwords for all the things that require one (esp. web > >> sites). > > > > You are digressing. Every password is important. Basing a password on > > the perceived imortance of an account is unwise. What Firefox has is of > > no great consequence when it comes to memorability. > > No, I am not digressing. Not every password is equally important. How > important is the password you use to post in a forum that you will not > visit again? Is it as important as the password of your GNU PG private key? Developing good practice with password management is what is important. If that weak password leads to a compromise of the account then it could end up with a ruined reputation for someone, depending on what happens. An ingrained habit of always creating a good password is a respectable life skill. > > Fine. But where is the improvement over > > > > Willhas5fingerson_each_Jand > > > > as a password? A bit longer to type, perhaps, but not spectacularly so. > > This is just for a block of 24 bits, thus this is a rough equivalent of > 4 characters under my method, which is *much* shorter to type. > > Assuming your mnemonic function is one-to-one (which it is not) you > would need 4 such to achieve the 96 bits of entropy that I recommend. > Then the difference in length is very significant. > > Moreover, since you are suggesting using the mnemonic itself, and the > mnemonic function is not well defined, the entropy is not well defined > either. The same password checker as above gives it the same rating and 132.4 bits of entropy. (Just saying. I'd accept that a checker's way of measuring entropy could be suboptimal. But that is a whole different topic). > ----- > Anyway, I posted this suggestion for those who want a provably (not > “probably”) secure password (up to a certain entropy). I know not > everybody will like my method, and that is fine for me. I actually like your method; its making the outcome of it memorable which I have difficulty with. I have no hesitation in saying the chances of my memorising u19rX2JjTM5salGIYfrO1w is nil. I suppose I could put more effort into forming a mnemonic, but I'd likely forget that too. On the other hand I could write it in my notebook. That's probably the way to go. Then I leave my notebook at home. "Probably" is probably good enough. The probability of either of the two previous passwords being deduced from pure guessing is close to zero. -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-23 20:00 +0200 |
| Message-ID | <uhI6B-3C9-11@gated-at.bofh.it> |
| In reply to | #185782 |
[Multipart message — attachments visible in raw view] — view raw
On 23/08/17 11:57, Brian wrote: >> If you do not care about security, you could generate a single 4 >> character bit block with my method and save typing. > > One online password checker (not that I understand how it works or even > trust it) gives > > IhaveaMemorablePasswordwhichIwillnotforget! > > 211.6 bits of entropy and rates it as "very strong" and "overkill". I'd > place any discomfort with having to type a long password low down on my > list password formation difficulties. Long, with some complexity and > memorable goes a long way to securing accounts on a computer or on the > web. Entropy is just another way of expressing probability. More specifically, entropy in bits is the logarithm in base 1/2 of the probability. It only makes sense to speak of probability (or equivalently, entropy) when there is a clearly defined probability distribution. The kind of passwords that you suggest are generated combining fragments of your knowledge in an ad-hoc way. Thus although we could *speak* of the probability distribution of your method, as applied by you, the actual probabilities are unknowable. The relevant probability distribution for password strength is the one that the attacker will assume. The online password checker has no way to know this, therefore the figures it gives are utter bullshit. Not only you should not trust it, you should ignore it completely. With my method, the probability distribution is well defined: Each character is chosen independently and uniformly distributed from a set of 64, thus it has 6 bits of entropy. >> No, I am not digressing. Not every password is equally important. How >> important is the password you use to post in a forum that you will not >> visit again? Is it as important as the password of your GNU PG private key? > > Developing good practice with password management is what is important. > If that weak password leads to a compromise of the account then it could > end up with a ruined reputation for someone, depending on what happens. > An ingrained habit of always creating a good password is a respectable > life skill. It is very ironic that you are now talking about the importance of strong passwords, while at the same time you advocate a non-well-defined method for password generation that probably gives weak passwords. As for the scenario where the password is compromised and that leads to somebody posting slander in one behalf, that can happen without any need for password cracking. Anybody can create a profile in a social network pretending to be you with the intention to taint your reputation. Hence that only your reputation as perceived by stupid people would suffer from such an attack. > I actually like your method; its making the outcome of it memorable > which I have difficulty with. I have no hesitation in saying the chances > of my memorising > > u19rX2JjTM5salGIYfrO1w > > is nil. I suppose I could put more effort into forming a mnemonic, but > I'd likely forget that too. On the other hand I could write it in my > notebook. That's probably the way to go. Then I leave my notebook at > home. I acknowledge that devising a mnemonic for the whole password in a single run is nor practical. Hence that my suggestion (which I already described in a previous message) is that if you need to memorize it instead of storing it in a password manager then you generate and memorize it by chunks of 4 characters. > "Probably" is probably good enough. The probability of either of the two > previous passwords being deduced from pure guessing is close to zero. It is not human guessing, but brute force attacks with specialized hardware what you should try to protect against. -- Do not eat animals, respect them as you respect people. https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2017-08-23 21:20 +0200 |
| Message-ID | <uhJm2-4yp-17@gated-at.bofh.it> |
| In reply to | #185785 |
On Wed 23 Aug 2017 at 12:58:19 -0500, Mario Castelán Castro wrote: > On 23/08/17 11:57, Brian wrote: > >> If you do not care about security, you could generate a single 4 > >> character bit block with my method and save typing. > > > > One online password checker (not that I understand how it works or even > > trust it) gives > > > > IhaveaMemorablePasswordwhichIwillnotforget! > > > > 211.6 bits of entropy and rates it as "very strong" and "overkill". I'd > > place any discomfort with having to type a long password low down on my > > list password formation difficulties. Long, with some complexity and > > memorable goes a long way to securing accounts on a computer or on the > > web. > > Entropy is just another way of expressing probability. More > specifically, entropy in bits is the logarithm in base 1/2 of the > probability. > > It only makes sense to speak of probability (or equivalently, entropy) > when there is a clearly defined probability distribution. > > The kind of passwords that you suggest are generated combining fragments > of your knowledge in an ad-hoc way. Thus although we could *speak* of > the probability distribution of your method, as applied by you, the > actual probabilities are unknowable. > > The relevant probability distribution for password strength is the one > that the attacker will assume. The online password checker has no way to > know this, therefore the figures it gives are utter bullshit. Not only > you should not trust it, you should ignore it completely. > > With my method, the probability distribution is well defined: Each > character is chosen independently and uniformly distributed from a set > of 64, thus it has 6 bits of entropy. To make progress. we should go along with that. > >> No, I am not digressing. Not every password is equally important. How > >> important is the password you use to post in a forum that you will not > >> visit again? Is it as important as the password of your GNU PG private key? > > > > Developing good practice with password management is what is important. > > If that weak password leads to a compromise of the account then it could > > end up with a ruined reputation for someone, depending on what happens. > > An ingrained habit of always creating a good password is a respectable > > life skill. > > It is very ironic that you are now talking about the importance of > strong passwords, while at the same time you advocate a non-well-defined > method for password generation that probably gives weak passwords. > > As for the scenario where the password is compromised and that leads to > somebody posting slander in one behalf, that can happen without any need > for password cracking. Anybody can create a profile in a social network > pretending to be you with the intention to taint your reputation. > > Hence that only your reputation as perceived by stupid people would > suffer from such an attack. A slander coming from your own (compromised) account is somewhat different from one posted from a created account. It is a lot harder to deny one but not the other. > > I actually like your method; its making the outcome of it memorable > > which I have difficulty with. I have no hesitation in saying the chances > > of my memorising > > > > u19rX2JjTM5salGIYfrO1w > > > > is nil. I suppose I could put more effort into forming a mnemonic, but > > I'd likely forget that too. On the other hand I could write it in my > > notebook. That's probably the way to go. Then I leave my notebook at > > home. > > I acknowledge that devising a mnemonic for the whole password in a > single run is nor practical. Hence that my suggestion (which I already > described in a previous message) is that if you need to memorize it > instead of storing it in a password manager then you generate and > memorize it by chunks of 4 characters. I am happy with that. > > "Probably" is probably good enough. The probability of either of the two > > previous passwords being deduced from pure guessing is close to zero. > > It is not human guessing, but brute force attacks with specialized > hardware what you should try to protect against. It is all "human guessing". Think about it. Machines do not guess by themselves. Not yet anyway! Two passwords: IhaveaMemorablePasswordwhichIwillnotforget! MyDogHasNoNose.HowDoesItSmell?Terrible! Please would you give your opinion of how long it would take to brute force these over the network. (I do not understand "specialized hardware" when it is network attacks.) -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-24 01:10 +0200 |
| Message-ID | <uhMWD-6Rd-25@gated-at.bofh.it> |
| In reply to | #185789 |
[Multipart message — attachments visible in raw view] — view raw
On 23/08/17 14:11, Brian wrote: >> As for the scenario where the password is compromised and that leads to >> somebody posting slander in one behalf, that can happen without any need >> for password cracking. Anybody can create a profile in a social network >> pretending to be you with the intention to taint your reputation. >> >> Hence that only your reputation as perceived by stupid people would >> suffer from such an attack. > > A slander coming from your own (compromised) account is somewhat > different from one posted from a created account. It is a lot harder > to deny one but not the other. The problem here is that only *you* know which account is legitimate and which is the impersonator. The rest of people read that account A claims that account B is impersonating it, but they can not know that is true, or whether it is actually the other way, or whether account B is actually the same person as account A but posing as a impersonator of himself (like the so called “self-robbery”). If you have access to an account, you can prove this easily to anybody through a challenge-response protocol. However, in general you can not prove that you do *NOT* have access to an account. It can be done only in *some cases*. For example, if you were unconscious in the hospital, the hospital personnel can attest to this. Of course, this works only if people is willing to trust the hospital personnel. >>> "Probably" is probably good enough. The probability of either of the two >>> previous passwords being deduced from pure guessing is close to zero. >> >> It is not human guessing, but brute force attacks with specialized >> hardware what you should try to protect against. > > It is all "human guessing". Think about it. Machines do not guess by > themselves. Not yet anyway! > > Two passwords: > > IhaveaMemorablePasswordwhichIwillnotforget! > > MyDogHasNoNose.HowDoesItSmell?Terrible! > > Please would you give your opinion of how long it would take to brute > force these over the network. > > (I do not understand "specialized hardware" when it is network attacks.) An answer can not be given for “how long it would take” because this question depends on too many factors. It is an open-ended question. Anyway, you have to take into account that sometimes a data base of hashed passwords of the users can be obtained through normal cracking. Then the attacker can perform a brute force search without any further need for network access. If your ~/.gnupg directory leaks, then your OpenPGP key is protected only by your password. No network access is required after the initial leak. -- Do not eat animals, respect them as you respect people. https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2017-08-24 19:50 +0200 |
| Message-ID | <ui4qu-1bx-21@gated-at.bofh.it> |
| In reply to | #185798 |
On Wed 23 Aug 2017 at 18:06:49 -0500, Mario Castelán Castro wrote: > On 23/08/17 14:11, Brian wrote: > >> As for the scenario where the password is compromised and that leads to > >> somebody posting slander in one behalf, that can happen without any need > >> for password cracking. Anybody can create a profile in a social network > >> pretending to be you with the intention to taint your reputation. > >> > >> Hence that only your reputation as perceived by stupid people would > >> suffer from such an attack. > > > > A slander coming from your own (compromised) account is somewhat > > different from one posted from a created account. It is a lot harder > > to deny one but not the other. > > The problem here is that only *you* know which account is legitimate and > which is the impersonator. The rest of people read that account A claims > that account B is impersonating it, but they can not know that is true, > or whether it is actually the other way, or whether account B is > actually the same person as account A but posing as a impersonator of > himself (like the so called “self-robbery”). > > If you have access to an account, you can prove this easily to anybody > through a challenge-response protocol. However, in general you can not > prove that you do *NOT* have access to an account. It can be done only > in *some cases*. For example, if you were unconscious in the hospital, > the hospital personnel can attest to this. Of course, this works only if > people is willing to trust the hospital personnel. It comes down (IME) to protecting and preserving one's online identity. Treating some accounts as deserving passw0rd while others get a urandom generated Odju56LAVGMXl8nJQBE4KA is not conducive to that. Also, taking shortcuts in health and safety matters rarely turn out well. > >>> "Probably" is probably good enough. The probability of either of the two > >>> previous passwords being deduced from pure guessing is close to zero. > >> > >> It is not human guessing, but brute force attacks with specialized > >> hardware what you should try to protect against. > > > > It is all "human guessing". Think about it. Machines do not guess by > > themselves. Not yet anyway! > > > > Two passwords: > > > > IhaveaMemorablePasswordwhichIwillnotforget! > > > > MyDogHasNoNose.HowDoesItSmell?Terrible! > > > > Please would you give your opinion of how long it would take to brute > > force these over the network. > > > > (I do not understand "specialized hardware" when it is network attacks.) > > An answer can not be given for “how long it would take” because this > question depends on too many factors. It is an open-ended question. Fair enough. > Anyway, you have to take into account that sometimes a data base of > hashed passwords of the users can be obtained through normal cracking. > Then the attacker can perform a brute force search without any further > need for network access. > > If your ~/.gnupg directory leaks, then your OpenPGP key is protected > only by your password. No network access is required after the initial leak. I'll give you that. 50,000 tests per second offline (or whatever it is now) beats an online attack of a few hundred (?) per second any day of the week. I've seen it said that a memorable password is a weak password. Perhaps there is some truth in that, but (again IME) it needn't be so. -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2017-08-25 03:00 +0200 |
| Message-ID | <uib8C-5ry-13@gated-at.bofh.it> |
| In reply to | #185848 |
On Thu 24 Aug 2017 at 18:42:47 (+0100), Brian wrote: > On Wed 23 Aug 2017 at 18:06:49 -0500, Mario Castelán Castro wrote: > > On 23/08/17 14:11, Brian wrote: > > > "Probably" is probably good enough. The probability of either of the two > > > previous passwords being deduced from pure guessing is close to zero. > > > > It is not human guessing, but brute force attacks with specialized > > hardware what you should try to protect against. [...] > > Anyway, you have to take into account that sometimes a data base of > > hashed passwords of the users can be obtained through normal cracking. > > Then the attacker can perform a brute force search without any further > > need for network access. > > > > If your ~/.gnupg directory leaks, then your OpenPGP key is protected > > only by your password. No network access is required after the initial leak. > > I'll give you that. 50,000 tests per second offline (or whatever it is > now) beats an online attack of a few hundred (?) per second any day of > the week. > > I've seen it said that a memorable password is a weak password. Perhaps > there is some truth in that, but (again IME) it needn't be so. Unless you have accounts¹ that invite break-in attempts², the main thing to resist offline cracking is to have better passwords than your neighbours, just like security against burglary. Once a suitable proportion of passwords have been cracked, which will consist of the easier ones, there are diminishing returns in continuing to try to crack the rest. ¹accounts of all sorts, not just forums. ²institutions, slebs, politicians, etc. Cheers, David.
[toc] | [prev] | [next] | [standalone]
Page 1 of 6 [1] 2 3 4 5 6 Next page →
Back to top | Article view | linux.debian.user
csiph-web