Live data from Hacker News

UK government's password checker sends plaintext password in the URL over HTTP

getsafeonline.org

111–117 of 117 posts

Re: UK government's password checker sends plaintext password in the URL over HTTP

#111
post #94
post #56

Earlier quoted context omitted.

I did a WHOIS, and seeing a domain registration date back to 2005 gave an air of credibility. So then I visited Internet Archive and browsed several pages https://web.archive.org/web/20080701000000*/http://getsafeon... They seem like experts... experts in subtle verbal manipulation for those without technical understanding, at least that is how it reads for me. Over years of archives, including the OP post, 'protect…

"We have short time to beat powerful computer attack" And see how pixelated their main banner image is? Not only bad grammar, but poor images. Really am ammeter website.

Here's an "ammeter" website for you: ammeters.compare99.com

Re: UK government's password checker sends plaintext password in the URL over HTTP

#112

Earlier quoted context omitted.

> but that concern is moot if you use unique words You could say the same thing about passwords using random characters. The problem isn't getting people to remember them, it's getting people to use random passwords/unique words in the first place. Telling people to "use a long sentence" will just result in them picking common sentences most of the time like "To be or not to be" or "Live long and prosper".

Well, let's say you have a 5-digit password made up of letters and numbers. That's 60466176 combinations. Now let's say you have a 4-word passphrase. There are about 120,000 words in English. There may be more if you include derivatives of words. That includes 2.0736e+20 combinations, not considering the entropy introduced by spaces between words or punctuation marks. That's just to demonstrate the power of passphras…

I think even the 20k most common estimate is way high. Think up some words yourself, and look them up in a frequency list. Most of the stuff I came up with of the top of my head was around 4-6k down the list. Look down to 20k and you get stuff like decorum, decked, daylights, daybreak, etc. When was the last time you heard anybody use those in a conversation?

I bet that with a little work, you could come up with a list a few thousand long that would get most of the passwords people come up with like that.

For my memorable passwords, I switched to using [0] pass phrase generator, which comes up with much rarer words than I do off the top of my head.

[0] http://www.fourmilab.ch/javascrypt/pass_phrase.html

[1] http://www.wordandphrase.info/frequencylist.asp

[2] http://en.wiktionary.org/wiki/Wiktionary:Frequency_lists

Re: UK government's password checker sends plaintext password in the URL over HTTP

#113

We should stop using the term "password" and start emphasizing pass phrases . A full sentence is much easier to remember, yet harder to crack, than a shorter, cryptic password. Or, as XKCD put it: http://xkcd.com/936/ There's a widespread misconception that words are always bad because of dictionary attacks, but that concern is moot if you use unique words or simply use a long sentence. A major advantage of sentences…

One problem with this is that most people are typing passwords on phones now, so the longer they are, they more annoying they are to type in. (Although I suppose word completion would help with a passphrase. Although for security it probably shouldn't be enabled for password fields.) Anyway, the real solution is a password manager with unique random sequences of characters for passwords.

Perhaps Microsoft, Apple, and Google could get together to build (or buy and open source) a password manager that would be integrated with their various platforms, for the common good. (I realize solutions already exist, but this would make it much more likely that the general public would use it.)

Re: UK government's password checker sends plaintext password in the URL over HTTP

#114
post #104
post #65

Earlier quoted context omitted.

For each rule in isolation, that's true enough. But the point stands: once you add together all those good practices (repetitions, consecutive letters, multiple character sets), how much does that actually reduce the password space? I'm not saying that the space becomes tiny, I'm saying that it becomes smaller, and I'm not sure whether "smaller" is still acceptably large, and it's an assumption that's worth checking.

The cost in entropy for these restrictions isn't zero, but it's tiny and measurable. As a conservative estimate, let's assume passwords are only chosen from a set of 84 printable ASCII characters and users never choose passwords longer than 10 characters. (If users are using characters outside this set or longer passwords, they'll have more choices than we're estimating.) All combinations, including the null password…

Thanks for doing my "homework" for me :). Interesting, I seriously expected the repetition and adjacency restrictions to add up to a much bigger cost, to be honest.

Re: UK government's password checker sends plaintext password in the URL over HTTP

#115
post #111
post #94

Earlier quoted context omitted.

"We have short time to beat powerful computer attack" And see how pixelated their main banner image is? Not only bad grammar, but poor images. Really am ammeter website.

Here's an "ammeter" website for you: ammeters.compare99.com

spell-check strikes again (dang keyboard!)

Re: UK government's password checker sends plaintext password in the URL over HTTP

#116
post #103

Earlier quoted context omitted.

Well, let's say you have a 5-digit password made up of letters and numbers. That's 60466176 combinations. Now let's say you have a 4-word passphrase. There are about 120,000 words in English. There may be more if you include derivatives of words. That includes 2.0736e+20 combinations, not considering the entropy introduced by spaces between words or punctuation marks. That's just to demonstrate the power of passphras…

> There are about 120,000 words in English [...] That includes 2.0736e+20 combinations You forgot using common sense: The number of words most people will actually choose to use is far fewer.

It sounds like you stopped reading my comment after the first paragraph. I later accounted for the reality that people have limited vocabularies.

Re: UK government's password checker sends plaintext password in the URL over HTTP

#117

Earlier quoted context omitted.

It IS "UK Government" - it's a QUANGO, so they can keep it at arms length and wash their hands of it, but be under no illusions, this is a government led initiative for which they ultimately, if not in practice, bear responsibility. The cynic in me says that this is a deliberate effort to grab as many passwords as possible. It sounds outlandish, but what actions of our rogue agencies haven't been?

That would be a waste of resources given the chances of a real criminal testing his/her password strength on a government-operated website are very remote. Even then, they would have to invest in marketing to get people to actually use it when, we all know now, the GHCQ/NSA can simply collect everything at critical infrastructure points. This looks like a good idea, poorly executed.

You think they're after "real criminals"? Tell me, what is this "real criminal" of what you speak? Is it someone who disagrees with the edicts of the state? Is it someone who has the wrong skin colour?

Occam's razor says you're right, but while they're busy accusing us all of criminal acts, we may as well do the same.

Post reply on HN