Live data from Hacker News

When it comes to composition and length, passwords mostly don't matter

techcommunity.microsoft.com

51–60 of 160 posts

Re: When it comes to composition and length, passwords mostly don't matter

#51

Earlier quoted context omitted.

This. I deal with relatively higher volumes of information that must remain secure. With google, I have hardware authentication device and 10 codes. Every 30 days or so it asks me to plug in the hardware device. Randomly it asks me more often - I have no idea why but no objection. My password is secure as well and only used on google but THANKFULLY I do not need to change it all the time and so I don't have to write…

> No SMS text option. ... ridicolous Agreed. My Twitter account was recently hacked thanks to T-Mobile's incompetence. [0] [0]: https://medium.com/@simon/mobile-twitter-hacked-please-help-...

I'm confused... because the whole reason your twitter was able to be hacked was because the SMS option allowed it to be hacked..

They stole your SIM. SMS option was now in their control.

SMS is not a secure 2FA option. sure its better than not having 2FA but only a little better.

Re: When it comes to composition and length, passwords mostly don't matter

#52

The number one reason I don't turn on MFA has nothing to do with the effort in entering the MFA code/pressing a confirm button. The lifecycle of MFA is the problem. The backup/recovery options are just terrible. You either print out a sheet of "one time codes" (which I need to not lose forever), my phone simply needs to never break, or I need to configure an insecure recovery account (creating a whole chicken/egg pro…

I was blown away when I discovered that there was no way for me to export my Google Authenticator TOTP secrets from my locked Android phone, since unlocking it wipes the disk. I guess I will not make the mistake of not immediately unlocking an Android phone again.

So what do you do? How did you get your account back?

Re: When it comes to composition and length, passwords mostly don't matter

#53

I think the thesis of this article is rather forced. The actual claim is something like: "Passwords don't matter, as long as your password isn't in the top few dozen common ones, it's not in any credentials breach accessible to attackers, it's longer than 8 characters or so, and you don't reuse it." That was a lot of criteria that seemed to matter, if you ask me.

And also "Passwords don't matter as long as you aren't important enough or connected to a person or organization important enough to try more than the most routine password vulnerabilities"

That would be a shocking statement to make. However, I don't see anything like that in the original article. Did I miss it somewhere?

Re: When it comes to composition and length, passwords mostly don't matter

#54

In my opinion, Microsoft's implementation of MFA on Office 365 (at least our instance) is broken. SMS MFA is inadequate and should not be used, the SS7 network is apparently trivially hackable in some circles and text messages can be rerouted. So they want us to use MS Authenticator, great. However the 365 login screen always has the "Sign in another way" option in which I can just bypass the Authenticator app and us…

> However the 365 login screen always has the "Sign in another way" option in which I can just bypass the Authenticator app and use an SMS text.

Not sure how that works if they (Microsoft) don’t have your phone number.

Re: When it comes to composition and length, passwords mostly don't matter

#55

Note this is from the perspective of a security decision maker, like an IT administrator. Policy-wise, users can't be forced or trusted to create excellent passwords on their own. But as an individual, your passwords do matter. It makes a world of a difference to use a password manager and long, completely random passwords - such passwords are immune to all sorts of cracking attempts, and using them can often make MF…

The point of the article is that many common attacks work just as well against completely random, unique passwords as they do against weak/reused ones. If you get phished, it doesn't matter if your password is strong. If your machine has a keylogger on it, it doesn't matter if your password is strong. Etc. Lots of attacks boil down to the attacker convincing you to unknowingly divulge your password, and if that passw…

> unknowingly divulge your password

What's to keep you from unknowingly divulging your MFA token's current generated code?

You're right that being phished/keylogged pwns a password-only account no matter how strong the password, but MFA isn't immune to phishing/keylogging/clipboard stealing either. Yes, the generated code will only give them access for 30 seconds (or whatever the algorithm's time window), but that's more than enough time for an attacker to get substantial work done.

I maintain that strong passwords in a password manager are probably good enough for security-conscious/appropriately skeptical people. For folks like that, MFA likely isn't worth the trouble - at least not quite yet.

Re: When it comes to composition and length, passwords mostly don't matter

#56

This is a good article. However, in regards to credential stuffing: > Some guidance says to ban all passwords on this list. Try that and see how successful your users are at choosing passwords at all. We're doing that. We don't let you choose any password that's been discovered in a prior breach. Did Microsoft implement the same thing and discover a high rate of users bouncing off the registration page?

Just idly wondering... I wonder how many AJAX style sites do password checking server side and send the password to the server in plain text...

Re: When it comes to composition and length, passwords mostly don't matter

#57
post #18

> Your password doesn’t matter, but MFA does! Based on our studies, your account is more than 99.9% less likely to be compromised if you use MFA. I'd be much more interested what that percentage is when you only consider people who use password managers. (Which is not to imply that MFA isn't good.)

Furthermore many sites make it difficult to use a password manager because it's hard to block automated password guessers and not interfere with password managers trying to enter passwords.

Trying to block automated password guessers on the client end is a fools errand anyway.

Re: When it comes to composition and length, passwords mostly don't matter

#58
post #18

> Your password doesn’t matter, but MFA does! Based on our studies, your account is more than 99.9% less likely to be compromised if you use MFA. I'd be much more interested what that percentage is when you only consider people who use password managers. (Which is not to imply that MFA isn't good.)

Furthermore many sites make it difficult to use a password manager because it's hard to block automated password guessers and not interfere with password managers trying to enter passwords.

My old bank used to "encrypt" your password as you typed it into the input field, on keydown it would take the character you typed and — and I'm not making this up — ROT13 it. This had the effect of making it impossible to paste anything into the input field since the script would capture your ctrl+v and replace it with the letter "i".

The icing on the cake is that when I called to complain about it, the support agent insisted in very sombre tones that it was a measure to stop keyloggers. I don't use that bank any more.

Re: When it comes to composition and length, passwords mostly don't matter

#59

Earlier quoted context omitted.

Eh... cars are really big. A better way of phrasing this is, "if this were true, your wallet/phone would get stolen a lot more often." But aren't wallet/phone thefts relatively common? > You're less secure from targeted attacks from people who know you IRL I'm also not completely certain this is true. If a YubiKey is the only thing securing most people's accounts, I don't need to target you. I can walk into a coffee…

A wallet is useful to a thief, a yubikey is not. There is little overlap between petty thieves and people trying to get into a particular target’s account.

> There is little overlap between petty thieves and people trying to get into a particular target’s account.

But isn't that the point? There's little overlap because right now we have a multi-factor system where stealing one part of the authentication mechanism from a random person in the street isn't enough to get into their account.

If everyone's account is secured with just a YubiKey, then you don't have to target a specific person. What's to prevent any petty thief from grabbing a bunch of wallets and/or YubiKeys, walking into a library, and just checking a few of the most common banks to see if any of them log in?

Maybe I'm missing something? It's not clear to me why an MFA attack would ever need to be targeted in a world without passwords. I guess maybe you're hoping that petty thieves can't figure out your username? But that's just treating your username like a password.

For a lot of bank accounts, your username will be some variant of your first and last name, which is helpfully printed on the drivers license in the wallet I just stole. I don't need to know who you are beforehand.

Re: When it comes to composition and length, passwords mostly don't matter

#60

In my opinion, Microsoft's implementation of MFA on Office 365 (at least our instance) is broken. SMS MFA is inadequate and should not be used, the SS7 network is apparently trivially hackable in some circles and text messages can be rerouted. So they want us to use MS Authenticator, great. However the 365 login screen always has the "Sign in another way" option in which I can just bypass the Authenticator app and us…

Can you explain this a bit further? We just switched to Office 365 and I ran into this today but I had assumed user error. So even though I have an authentication key set up there’s always the possibility that a password reset can be authenticated via my phone number?

Pretty sure you can remove sms from the 2fac process by going to:

My Account > Security & Privacy > Additional Security Verification > Update Your Phone Numbers Used for Account Security

And then setting the preferred method to "use verification code from app". Once you finish setting up the authenticator app you can delete your phone number from the 2fac list.

At the end of that process you should be left with only having the app authenticator as a 2fac option.

See https://docs.microsoft.com/en-us/azure/active-directory/user... for some details, but the MSFT documentation on this isn't very good in general.

Post reply on HN