VaultNetwork.netVault Network Boards
Author Topic: Is this true? [Locked]
vn_jurojin  1 star
Title: Insolent Insomniac
Posts: 205
Registered: 2001-12-20 03:26:39
http://xkcd.com/936/

And if so, why is everyone else on the planet wrong?
Aerlinthian  4 stars
Posts: 2,126
Registered: 2001-5-7 23:53:38
That is rather interesting. I won't change my password strategy because there is no need to but if I were to, I would consider this strategy.
Steelwind_Oo  4 stars
Title: Lurking Oo
Posts: 1,789
Registered: 2000-9-30 10:26:30
It makes a lot of assumptions to try to prove a point but yeah if you formatted your passwords exactly like described in the comic and they knew you formatted your password exactly like that then it would be easier to crack. That said most people do just use one word in leet speak and think they are good. Mine are sorta like that but with more variables that would make it much harder.

Even then looking at the comic it seems off in how it accounts for the variables. For example they assign 3 bits for common substitutions when in reality it could be more than that since there are more possible substitutions and some words have more substitutable letters than others. A word with more 'leetable' letters would be considerably harder.

A random string of words works if it is truly random otherwise a little knowledge about the user or their environment could build a pretty solid dictionary or even a common dictionary style attack. That of course assumes you know roughly how many words are used too but that could be guessed, or at least restricted, based on password length requirements for the system in question.

 

-----signature-----
'God is an imaginary friend for grownups.', Walter Crewes (Morgan Freeman), The Big Bounce
Don't be afraid to ask dumb questions they're easier to handle than dumb mistakes!
Xbox 360 Gamer Tag: SteelwindOo
e93% a53% s33% k13%
Marzuk  1 star
Posts: 153
Registered: 2002-10-21 16:08:17
http://www.codinghorror.com/blog/2005/07/passwords-vs-pass-phrases.html

I'd say its correct in the general idea, though it may be a bit off on the math the theory is sound.

Its mostly academic anyway. Any *reasonable* login will cut you off after 10 or so attempts, so your ability to try a massive number of passwords is pathetic. The calculations all assume you can do the attempts instantly.

As a side note, I see your comic about password security and raise you:

http://xkcd.com/538/
vn_jurojin  1 star
Title: Insolent Insomniac
Posts: 205
Registered: 2001-12-20 03:26:39
^ lol
Jyiiga  2 stars
Title: The MMO Snob
Posts: 374
Registered: 2001-3-15 22:36:09
More or less correct, but as someone already pointed out just about everything limits you number of wrong replies.

After 4-5 guesses they either lock your account or you get those image verification thingies.

 

-----signature-----
Seffrid  1 star
Title: Ancient One
Posts: 111
Registered: 2001-12-21 08:33:14
Guesswork is so last season where password hacking is concerned. Far better to steal the entire password database instead - and in those circumstances the idea of one password being "strong" while another password is "weak" is a joke.
Karsus_the_Great  1 star
Title: This is a title.
Posts: 76
Registered: 2003-4-12 21:33:04
Seffrid posted:

Guesswork is so last season where password hacking is concerned. Far better to steal the entire password database instead - and in those circumstances the idea of one password being "strong" while another password is "weak" is a joke.



Sadly this, which is why FDE is so much so a requirement.

You should be getting your passwords from this, or something like it.

 

-----signature-----
I know I'm going to hell, I'll bring marshmallows.
Caldari. The only race in Eve that does not fly it's own ships.
Karsus the Great - lvl 240+ Original BM(retired)
Lonestar_1  2 stars
Posts: 259
Registered: 2004-8-26 08:40:28
The best thing you can do is not use the same password everywhere, even vary your account name if that worried. And make sure you try not to use any personal info when creating the passwords.

This limits the damage of a compromised account to just that location.

 

-----signature-----
http://gimpchimp.etilader.com/display.php?user=lonestarr
3500+ solo kills & Lone Enforcer
WAR - IronRock Dest- Energist, Moogabooga
SWTOR - KV - Energist, Moogabooga
Marzuk  1 star
Posts: 153
Registered: 2002-10-21 16:08:17
Seffrid posted:

Guesswork is so last season where password hacking is concerned. Far better to steal the entire password database instead - and in those circumstances the idea of one password being "strong" while another password is "weak" is a joke.



Depends on how the password was stored. Proper hash + salt is going to at least make it prohibitive to recover passwords from a database dump. And I'm not talking an MD5.

VaultNetwork.net is an independently operated community forum and is not affiliated with, endorsed by, or technically based on IGN, GameSpy, FilePlanet, GameStats, or the former IGN/GameSpy Vault Network.
References to VaultNetwork.net mean this site/domain. VNBoards-style presentation is a visual homage only. By using this site, you agree to the forum rules.