Earlier quoted context omitted.
I did a WHOIS, and seeing a domain registration date back to 2005 gave an air of credibility. So then I visited Internet Archive and browsed several pages https://web.archive.org/web/20080701000000*/http://getsafeon... They seem like experts... experts in subtle verbal manipulation for those without technical understanding, at least that is how it reads for me. Over years of archives, including the OP post, 'protect…
"We have short time to beat powerful computer attack" And see how pixelated their main banner image is? Not only bad grammar, but poor images. Really am ammeter website.
UK government's password checker sends plaintext password in the URL over HTTP
111–117 of 117 posts
Re: UK government's password checker sends plaintext password in the URL over HTTP
#112Earlier quoted context omitted.
> but that concern is moot if you use unique words You could say the same thing about passwords using random characters. The problem isn't getting people to remember them, it's getting people to use random passwords/unique words in the first place. Telling people to "use a long sentence" will just result in them picking common sentences most of the time like "To be or not to be" or "Live long and prosper".
Well, let's say you have a 5-digit password made up of letters and numbers. That's 60466176 combinations. Now let's say you have a 4-word passphrase. There are about 120,000 words in English. There may be more if you include derivatives of words. That includes 2.0736e+20 combinations, not considering the entropy introduced by spaces between words or punctuation marks. That's just to demonstrate the power of passphras…
I bet that with a little work, you could come up with a list a few thousand long that would get most of the passwords people come up with like that.
For my memorable passwords, I switched to using [0] pass phrase generator, which comes up with much rarer words than I do off the top of my head.
[0] http://www.fourmilab.ch/javascrypt/pass_phrase.html
[1] http://www.wordandphrase.info/frequencylist.asp
[2] http://en.wiktionary.org/wiki/Wiktionary:Frequency_lists
Re: UK government's password checker sends plaintext password in the URL over HTTP
#113We should stop using the term "password" and start emphasizing pass phrases . A full sentence is much easier to remember, yet harder to crack, than a shorter, cryptic password. Or, as XKCD put it: http://xkcd.com/936/ There's a widespread misconception that words are always bad because of dictionary attacks, but that concern is moot if you use unique words or simply use a long sentence. A major advantage of sentences…
Perhaps Microsoft, Apple, and Google could get together to build (or buy and open source) a password manager that would be integrated with their various platforms, for the common good. (I realize solutions already exist, but this would make it much more likely that the general public would use it.)
Re: UK government's password checker sends plaintext password in the URL over HTTP
#114Earlier quoted context omitted.
For each rule in isolation, that's true enough. But the point stands: once you add together all those good practices (repetitions, consecutive letters, multiple character sets), how much does that actually reduce the password space? I'm not saying that the space becomes tiny, I'm saying that it becomes smaller, and I'm not sure whether "smaller" is still acceptably large, and it's an assumption that's worth checking.
The cost in entropy for these restrictions isn't zero, but it's tiny and measurable. As a conservative estimate, let's assume passwords are only chosen from a set of 84 printable ASCII characters and users never choose passwords longer than 10 characters. (If users are using characters outside this set or longer passwords, they'll have more choices than we're estimating.) All combinations, including the null password…
Re: UK government's password checker sends plaintext password in the URL over HTTP
#115Earlier quoted context omitted.
"We have short time to beat powerful computer attack" And see how pixelated their main banner image is? Not only bad grammar, but poor images. Really am ammeter website.
Here's an "ammeter" website for you: ammeters.compare99.com
Re: UK government's password checker sends plaintext password in the URL over HTTP
#116Earlier quoted context omitted.
Well, let's say you have a 5-digit password made up of letters and numbers. That's 60466176 combinations. Now let's say you have a 4-word passphrase. There are about 120,000 words in English. There may be more if you include derivatives of words. That includes 2.0736e+20 combinations, not considering the entropy introduced by spaces between words or punctuation marks. That's just to demonstrate the power of passphras…
> There are about 120,000 words in English [...] That includes 2.0736e+20 combinations You forgot using common sense: The number of words most people will actually choose to use is far fewer.
Re: UK government's password checker sends plaintext password in the URL over HTTP
#117Earlier quoted context omitted.
It IS "UK Government" - it's a QUANGO, so they can keep it at arms length and wash their hands of it, but be under no illusions, this is a government led initiative for which they ultimately, if not in practice, bear responsibility. The cynic in me says that this is a deliberate effort to grab as many passwords as possible. It sounds outlandish, but what actions of our rogue agencies haven't been?
That would be a waste of resources given the chances of a real criminal testing his/her password strength on a government-operated website are very remote. Even then, they would have to invest in marketing to get people to actually use it when, we all know now, the GHCQ/NSA can simply collect everything at critical infrastructure points. This looks like a good idea, poorly executed.
Occam's razor says you're right, but while they're busy accusing us all of criminal acts, we may as well do the same.