Live data from Hacker News

Lessons from a Professional Password Cracker

themarkup.org

101–110 of 138 posts

Re: Lessons from a Professional Password Cracker

#101
post #75

Yubikey is here since 2007... and Windows 10 still doesn't support passwordless, security key only! login. They want you to register a goddamn MS account too...

Windows has supported smartcard logins since at least 2000, should work fine with yubikeys too. https://support.yubico.com/hc/en-us/articles/360013707820-Yu...

Microsoft Outlook and live.com logins can use security keys, in fact they are accepted as a single authentication factor rather than a second one: supply your Yubikey and you're logged in without username or password!

However, Windows Hello in Windows 10 does not support local logins with security keys. This may have changed last week with a recent update, but it definitely wasn't supported when I installed Windows last Christmas.

I think it's Microsoft's opinion that security keys are too secure for consumer use; if a consumer is locked out of their personal device due to mismanagement, theft or loss of a hardware key, that's a support headache and liability burden that they're unwilling to take on at this point.

Re: Lessons from a Professional Password Cracker

#103
post #77

Earlier quoted context omitted.

I think windows encrypts more and more by default. TPMs are not unlocked if they can't validate the boot chain (live cd), so you'd need the disk password (and full user password).

dont you disable secure boot and go to legacy mode ? i do when i install linux or windows both as a habit

I haven't performed a single windows install since 2013ish (was it 8.0 beta?), but I'm saying this based on how often I see it enabled. Companies do it, and probably manufacturers too. I'm less sure about the install media, true.

Regarding secureboot, I went through the pain of configuring it under Linux (creating and importing my own keys), before realizing it was of little use without a TPM. Turns out both Windows and Linux can't "own" the TPM at the same time, IIRC (work laptop has a windows partition). I ended up learning my randomly generated >15 char disk decryption password by heart.

Re: Lessons from a Professional Password Cracker

#104

Slightly off topic but it made me smile: The linked Diceware website run by the daughter has press links about the $2 passwords she sells. The FAQ notes the passwords are $4 a pop. The actual price: $8

I feel now is the time to shill my free cloud, 18-character length password generator [1]. It is a completely serious password generator only requiring a Twitter mention (@) to summon.

Paid premium extends this to 21 characters.

1: https://twitter.com/generatepw

Re: Lessons from a Professional Password Cracker

#105

Earlier quoted context omitted.

Don't worry, all I can see is ••••••••••••. The browser builds in technology so that it conveniently shows you your password (BingoBingo77), but all I can see is ••••••••••••. Neat, right?

> Don't worry, all I can see is ••••••••••••. The browser builds in technology so that it conveniently shows you your password (BingoBingo77), but all I can see is ••••••••••••. Neat, right? Hey, waitaminute! How did you know that my password is "BingoBingo77"[1]. [1] It shows as •••••••••••• to every one but me?

He just copy-pasted your ••••••••••••'s and it appears to you as BingoBingo77 cause it's your password.

Re: Lessons from a Professional Password Cracker

#106
post #65
post #56

Earlier quoted context omitted.

The worst thing about biometrics or hardware devices is that someone can force you to give them out in my opinion. If I have a 6 word passphrase which I remembered, no one can get it unless I give it to them (Yeah, I know there's still some methods https://xkcd.com/538/ ).

Indeed. Also in legal terms. In the Netherlands, the police can hold your finger to the fingerprint reader on a device they confiscated (might need a court order, or might depend on circumstances if there is an imminent threat to life or something), but they cannot order you to work on your own prosecution in general. Why, then, you can be ordered to put your finger on the pad, I have no idea, but it has been ruled t…

The solution there is to set aside a few less-used fingers which, when applied to the scanner in sequence, tell it to perform a secure wipe. I'm left-handed so I use a few fingers on my right hand plus my left little finger for access, this leaves enough fingers for a fingerprint-directed wipe command:

   left index followed by
   left ring followed by
   left middle => Wipe
There is bound to be an app or option in some AOSP-derived distribution for that, if not you got the idea here.

Re: Lessons from a Professional Password Cracker

#107

Earlier quoted context omitted.

We have the following: Authenticator app, HID card, or FIDO key. Biometric is coming but the goal is to not have to give people yet another reader/device. In theory we wouldn't have to worry about someone losing their card or key but they don't always setup all three in their account.

Are these used in conjuction, or any one will do? If it's the former, it seems like it would make the problem of loss worse. If it's the latter, then it seems you've offered a variety of ways that someone can access your systems - steal a key, copy biometrics, guess the phone password etc. - the weakest one will do.

You only need to use one. You need a PIN to use any of the devices as well.

Re: Lessons from a Professional Password Cracker

#108
post #32

Earlier quoted context omitted.

Something I’ve wished companies would do: publish (on an internal site) all of their employees’ previous passwords each time they’re rotated. Users would be compelled to create better passwords out of sheer embarrassment/competitive spirit.

Plus, it would mean people would stop just incrementing a number at the end if it revealed their pattern.

You underestimate how much people care about a revealed password. I've definitely heard water cooler talk about how some have "beat the system" by using a certain password (That they just tell the person they're talking to!) and the year.

Re: Lessons from a Professional Password Cracker

#109

Earlier quoted context omitted.

Did a Windows 10 Pro install just a couple days ago and BitLocker still wasn't on by default.

I think it's only turned on when you connect it to an online account. It's still possible to only use a local one, but it's in an unexpected place, so I expect most people to go the online route.

indeed, only when using a microsoft account, which by the way is now required in the latest isos. you can still bypass it but it requires being offline for the install. that being said, there are still many laptops with older windows version preinstalled that do not have the requirement; however users that don't care about this will just click the MS account option because the button was kind of hidden.

their reason for this is that you need to save the bitlocker recovery key somewhere, and they don't trust the users to do it properly (not even mentionning the UI for this would be horrendous) so it saves it to OneDrive.

Re: Lessons from a Professional Password Cracker

#110
post #26
post #15

shameless plug: the EFF sells a dice set and fun sticker for use with their wordlist. https://www.eff.org/dice

Nice. Seems to be a real improvement over diceware. > We manually checked and attempted to remove as many profane, insulting, sensitive, or emotionally-charged words as possible, and also filtered based on several public lists of vulgar English words I kind of wish they had a list _without_ this step though. Vulgar and emotionally charged words are easy to work into stories and easy to remember.

[deleted]
Post reply on HN