Live data from Hacker News

Lessons from a Professional Password Cracker

themarkup.org

81–90 of 138 posts

Re: Lessons from a Professional Password Cracker

#81

I use this password for all my accounts: BingoBongo77. Is it secure? Edit: oh crap

Don't worry, all I can see is ••••••••••••. The browser builds in technology so that it conveniently shows you your password (BingoBingo77), but all I can see is ••••••••••••. Neat, right?

> Don't worry, all I can see is ••••••••••••. The browser builds in technology so that it conveniently shows you your password (BingoBingo77), but all I can see is ••••••••••••. Neat, right?

Hey, waitaminute! How did you know that my password is "BingoBingo77"[1].

[1] It shows as •••••••••••• to every one but me?

Re: Lessons from a Professional Password Cracker

#82
post #77

Earlier quoted context omitted.

the thief can just use a live cd and copy stuff, i mean that is what i do when i bork the windows install. i don't use bitlocker and i suspect many many people don't so this is merely an inconvenience

I think windows encrypts more and more by default. TPMs are not unlocked if they can't validate the boot chain (live cd), so you'd need the disk password (and full user password).

Did a Windows 10 Pro install just a couple days ago and BitLocker still wasn't on by default.

Re: Lessons from a Professional Password Cracker

#83
post #17

Hey, I keep seeing people claim biometrics somehow fix the password problem, but I feel like this is just a password you can't change? I can't change my fingerprints nor my retina, but if that data ever gets leaked, then that's vulnerable forever? In my mind, there's no world where one could make a biometric scanner that couldn't be spoofed (presumably with an arduino USB interface) and then when all these corporatio…

Generally, you're not logging in directly with the biometric data. The biometric data never leaves your device, it is just used to protect some kind of secret key on the local device that it actually uses for the authentication when logging in. If you need to log in another device, you would use an existing device to confirm the new login or you would need to use some other authentication method.

Well, I got fingerprinted by FINRA when I took a job at a trading company, and I have been fingerprinted by the US government multiple times. When I went through China once, they needed a fingerprint or two. Same for my Brazilian visa.

Biometric information leaks through other means, and if you rely on it for security, you are letting a lot of people in.

Re: Lessons from a Professional Password Cracker

#84
This all comes down to this statement:

>In fact, pretty much the only case where complexity and length matter is when we’re defending against offline password cracking. But for every other case in the threat model where passwords are stolen, length and complexity simply don’t matter.

The idea is that most passwords are stolen when they are plaintext. So it only matters that the password is unique to that system. Offline password cracking is relevant for cases like the passphrase used to protect your PGP or SSH keys. Then length and complexity is important. Stuff like the suggested FIDO is the same sort of thing. If you need to protect the FIDO key information then length and complexity of your passphrase is important where offline password cracking is relevant.

Re: Lessons from a Professional Password Cracker

#85
post #19

I'm surprised a password cracker would advocate switching to biometrics, the one type of password you can't change.

Most modern biometric auth is implemented by the biometric device acting as an HSM and only agreeing to perform the cryptographic operation with its secrets if the proper biometrics are provided. Biometrics are never directly sent to the service you're authenticating to, instead it's using a form of PKI in the background where your biometric device is an HSM storing the client certificate.

This is less secure against dedicated attackers with physical access, but much more secure against remote attackers as there's usually no way to provide the biometrics to the HSM in software and the authentication key from the biometric device can't be stolen so you must keep persistent access to it to be able to use it every time you need to authenticate.

Re: Lessons from a Professional Password Cracker

#86
post #74
post #17

Hey, I keep seeing people claim biometrics somehow fix the password problem, but I feel like this is just a password you can't change? I can't change my fingerprints nor my retina, but if that data ever gets leaked, then that's vulnerable forever? In my mind, there's no world where one could make a biometric scanner that couldn't be spoofed (presumably with an arduino USB interface) and then when all these corporatio…

It's a solved problem in a minor baltic state. We have id card, which contains client authentication certificates. The procedure on acquiring ID card is the same as passport and carries the same legal power. You have to show up in real life and they take your fingerprints, photo and issue you ID card. ID cards will actually be mandatory for everyone beginning 2023-01-01 - up until now they are optional but very much…

This is The Correct Answer™.

CA issued GUIDs unlocks the Translucent Database technology, enabling all PII to be encrypted AT REST at the field level.

Translucent Databases 2/e: Confusion, Misdirection, Randomness, Sharing, Authentication And Steganography To Defend Privacy Paperback [2009]

https://www.amazon.com/Translucent-Databases-2Nd-Authenticat...

PS- Just spotted ftrotter's question for the first time. I also worked in healthcare IT and prototyped a PII protecting schema. Alas, my POC also flew like a lead zepplin. No password recovery. This strategy requires GUIDs, aka RealID in the USA.

https://stackoverflow.com/questions/2109451/translucent-data...

"I am building an application with health information inside. This application will be consumer-facing with is new for me. I would like a method to put privacy concerns completely at ease. As I review methods for securing sensitive data in publicly accessible databases I have frequently come across the notion of database translucency. ..."

I could have written that. Oh well. Someone in much the same situation, having the same questions, and then reaching about the same answer is somewhat validating.

10+ years later, I'm sure there's now dozens of us advocating Translucent Databases techniques.

Re: Lessons from a Professional Password Cracker

#87
post #77

Earlier quoted context omitted.

the thief can just use a live cd and copy stuff, i mean that is what i do when i bork the windows install. i don't use bitlocker and i suspect many many people don't so this is merely an inconvenience

I think windows encrypts more and more by default. TPMs are not unlocked if they can't validate the boot chain (live cd), so you'd need the disk password (and full user password).

dont you disable secure boot and go to legacy mode ? i do when i install linux or windows both as a habit

Re: Lessons from a Professional Password Cracker

#88
post #77

Earlier quoted context omitted.

I think windows encrypts more and more by default. TPMs are not unlocked if they can't validate the boot chain (live cd), so you'd need the disk password (and full user password).

Did a Windows 10 Pro install just a couple days ago and BitLocker still wasn't on by default.

I think it's only turned on when you connect it to an online account.

It's still possible to only use a local one, but it's in an unexpected place, so I expect most people to go the online route.

Re: Lessons from a Professional Password Cracker

#89
post #77

Earlier quoted context omitted.

I think windows encrypts more and more by default. TPMs are not unlocked if they can't validate the boot chain (live cd), so you'd need the disk password (and full user password).

dont you disable secure boot and go to legacy mode ? i do when i install linux or windows both as a habit

On my work laptop, on which I dual boot Arch and Windows, I've just signed MS's keys with my own key and disabled booting from anything else than the internal drive.

I'm not sure what you mean by "legacy mode", but I'd expect that to mean "BIOS compatibility mode", and that's not really related (apart from presumably disabling secure boot). I actually prefer UEFI, this allows me to avoid wasting time with a classic bootloader.

Re: Lessons from a Professional Password Cracker

#90
post #45

Earlier quoted context omitted.

Something I’ve wished companies would do: publish (on an internal site) all of their employees’ previous passwords each time they’re rotated. Users would be compelled to create better passwords out of sheer embarrassment/competitive spirit.

I sort of wish companies would not have employees passwords. Hashing should be standard practice.

It must be, but publishing old passwords can still be done by saving the old cleartext password on password change.
Post reply on HN