Live data from Hacker News

Passphrases You Can Memorize That Even the NSA Can’t Guess

firstlook.org

41–50 of 57 posts

Re: Passphrases You Can Memorize That Even the NSA Can’t Guess

#41

Earlier quoted context omitted.

A line from a song is far weaker entropy-wise due to grammar. I wonder by how much. Common songs/writings would be vulnerable to a dictionary type attack. As for the hundreds of passwords in your list, I'm convinced a password manager with a master password/3rd party auth/dongle is the way to go. Otherwise it's impossible to have unique passwords for all sites, rotate them, and remember them. Of course the risk is of…

> A line from a song is far weaker entropy-wise due to grammar. Interesting observation, the usual objection is due to the reduced Kolmogorov complexity which is difficult to quantify. Let's look at a modified diceware scheme of the form: Article adjective noun adverb verb adjective noun A (non-random) example might be: The young boy really likes video games. I'm not going to go through the diceware word list and cla…

Interesting, I really like your approach to this.

If we go back to the original 'song verse' idea, the space of all valid/written phrases is much smaller than the space of all possible word combinations. It's vulnerable to dictionary attacks based on commonly chosen phrases and frequency of phrase use in language/culture.

Wikipedia only has 2.4 billion words, out of an estimated billion English words [1]. Perhaps we could add project Gutenberg with it's 50,000 works, and all the song lyrics we could find on the internet. We may hit 5 billion words. Let's estimate we also get 5 billion 6-word phrases out of that set. We've lost a ton of entropy.

Ultimately, we suck at passwords. Machine capability will exceed what we can reliably, efficiently memorize.

[1] http://www.languagemonitor.com/number-of-words/number-of-wor...

Re: Passphrases You Can Memorize That Even the NSA Can’t Guess

#43

Earlier quoted context omitted.

A line from a song is far weaker entropy-wise due to grammar. I wonder by how much. Common songs/writings would be vulnerable to a dictionary type attack. As for the hundreds of passwords in your list, I'm convinced a password manager with a master password/3rd party auth/dongle is the way to go. Otherwise it's impossible to have unique passwords for all sites, rotate them, and remember them. Of course the risk is of…

> A line from a song is far weaker entropy-wise due to grammar. Interesting observation, the usual objection is due to the reduced Kolmogorov complexity which is difficult to quantify. Let's look at a modified diceware scheme of the form: Article adjective noun adverb verb adjective noun A (non-random) example might be: The young boy really likes video games. I'm not going to go through the diceware word list and cla…

I wonder how many nouns, verbs, and adjectives we can dig up? Can we dig up 7776 each?

While I think the set of adverbs would be much smaller (and obviously the set of articles will be very small) you could easily approach the same entropy as the Diceware method with a longer phrase. So long as there are 7 words in the phrase with 7776 possibilities each, you're equivalent. The rest is mnemonic glue.

Since I think nouns are going to be the easiest set, shooting for something even more noun heavy could help.

Edit: though since you're now syntactically more likely to be used in the wild, you'd probably want to search to make sure the phrase wasn't used in some other source. Problem there is the search leaks your password...

Re: Passphrases You Can Memorize That Even the NSA Can’t Guess

#44
In practice this would take longer than the 27 million years stated assuming 2 things: that the computer doing the guessing doesn't try passphrases it has tried in the past and that the user changes their password at least 1 time (more likely multiple times) within the 27 million years. This is contingent upon somehow not changing your passphrase to a passphrase much much higher up on the list of what the computer will try to guess. What are the chances of this occurring and what are the chances of the opposite occurring where the user's correct passphrase is somehow next on the list yet at that time the user randomly changes it to the passphrase at the very end of the list? Would this then mean it is better to keep the same passphrase forever or to change it?

Re: Passphrases You Can Memorize That Even the NSA Can’t Guess

#45
Reading this, I just thought of another way to make passphrases that might be a bit more memorable. The idea is to come up with a sentence which will be grammatically correct, so it'll be easier to remember.

First, write down 36 words. Roll two dice, take six times the number on the first minus the number on the second plus one. That is the position in the list of the first word in the sentence.

Next, write a new list of 36 words, but only include words that make sense given what is already there. Roll again as before and pick as before. Reusing words between lists is fine, but don't include the same word in the same list multiple times.

Rinse and repeat until you have the desired amount of entropy. Each die thrown adds log_2 6 bits.

Edit, just tried this, 36 is a lot of words to come up with. Much easier to write down 6 at the cost of making it twice as long. Unless you have access to lists of nouns, verbs, etc.

Bored now, but came up with "Countries can slowly sit at my feet", 24 bits of entropy (some lists had 36 words others had 6. It's very low, but, if you did that 2 or 3 times, you'd be getting somewhere). Couldn't be easier to remember.

Re: Passphrases You Can Memorize That Even the NSA Can’t Guess

#46

Earlier quoted context omitted.

> A line from a song is far weaker entropy-wise due to grammar. Interesting observation, the usual objection is due to the reduced Kolmogorov complexity which is difficult to quantify. Let's look at a modified diceware scheme of the form: Article adjective noun adverb verb adjective noun A (non-random) example might be: The young boy really likes video games. I'm not going to go through the diceware word list and cla…

Interesting, I really like your approach to this. If we go back to the original 'song verse' idea, the space of all valid/written phrases is much smaller than the space of all possible word combinations. It's vulnerable to dictionary attacks based on commonly chosen phrases and frequency of phrase use in language/culture. Wikipedia only has 2.4 billion words, out of an estimated billion English words [1]. Perhaps we…

This is the more usual objection that I was referring to with Kolmogorov complexity. Forty random digits has very decent entropy, 40 digits of PI, though they look very random, has much less. From that you can see how it's really hard to quantify exactly how much entropy there is an song verse that exists somewhere on the internet.

If you wanted an absolute ranking of password strength, you'd first want to construct a universal brute force dictionary of passwords. Clearly the password 'password' is going to be near the beginning of the list and a password consisting of 48 randomly picked characters from [a-zA-Z0-9!@#$%^&*()] is likely to be somewhere out beyond the number of particles in the universe. But where exactly is "When you ain't got nothing, you got nothing to lose" going to appear? The first 10 million? billion? 10 billion? trillion? I really have no idea.

Re: Passphrases You Can Memorize That Even the NSA Can’t Guess

#47
The official website of Diceware does not have a certificate http://world.std.com/~reinhold/diceware.html Is it intentional ?

The word list is signed but for someone unfamiliar with crypto an electronic signature is useless while a lock in the address bar is reassuring.

Re: Passphrases You Can Memorize That Even the NSA Can’t Guess

#48

Their are two levels of security, Mossad and non-Mossad. Worrying about evading the NSA is premature optimization at best and a form of mental illness at worst.

Other than it not being tinfoil after the past 2-15 years of evidence that citizens are targeted, it's not unreasonable to assume that the public is "only" 10-20 years behind the NSA when it comes to technology. So unless you have lifecycle management on all your encrypted files, and plan on regular password rotation on everything on your hard drive that you keep encrypted, perhaps it's not unreasonable to use something secure and memorable NOW.

Re: Passphrases You Can Memorize That Even the NSA Can’t Guess

#49
This doesn't stop the biggest threat against a government-sponsored entity: if they really want to break into your data, they'll just install a key logger into your bios or some other crazy shit like that.

All these nice pass-phrases do is protect you against people that get big user dumps of hashes like we saw with the recent Slack security breach.

The NSA doesn't need to guess your passphrase. The Chinese equivalent doesn't need to either. They'll just literally watch you type it in. Or use existing vulnerabilities to capture the traffic at your border router. And if you're REALLY a person of interest, they'll just use their CIA equivalent to capture you and torture the information out of you.

Post reply on HN