Except it's not going to work, because of the bank who doesn't allow '(' as a special character, or the ticket website that requires at least 3 digits, or the financial firm who only allows 8 character passwords. As soon as you have a few sites with 'rogue' password policies, the system breaks down.
A plastic card for easy to remember strong passwords
81–90 of 110 posts
Re: A plastic card for easy to remember strong passwords
#82Re: A plastic card for easy to remember strong passwords
#83This is a substitution cipher and it's not very secure. Consider what we can do if we compromise the Amazon password that's given as an example on the website: sh(/J3HqAfQsu..u.rqf Since the password came from Amazon, we know that the last 6 characters are "Amazon," which tells us that: . = A u = M r = Z q = O f = N Now we can start attacking the codeword, which are the characters between the 8-character "space bar c…
This sort of objection is raised whenever basically any mechanism for remembering strong passwords is presented. Much like many results in computational complexity, worst-case results are not necessarily indicative of real-world utility. To wit, in the scenario you outlined the attacker must a) know beforehand that the target was using this device; b) know beforehand that the inserted middle portion was vulnerable to…
Then again there are different kinds of attack on passwords, among those is the dedicated targeted attack and those will be happy to exploit the false sense of security you get from a qwerty card.
Now if you want a practical alternative for choosing passwords you can remember: https://www.schneier.com/blog/archives/2014/03/choosing_secu...
Lastly using the same password for everything is wrong, but reusing a password for services that do not require a high level of security is acceptable such as posting comment on weblogs. bugmenot being a popular choice reminding of a time when their website was actually useful.
Re: A plastic card for easy to remember strong passwords
#84Earlier quoted context omitted.
This sort of objection is raised whenever basically any mechanism for remembering strong passwords is presented. Much like many results in computational complexity, worst-case results are not necessarily indicative of real-world utility. To wit, in the scenario you outlined the attacker must a) know beforehand that the target was using this device; b) know beforehand that the inserted middle portion was vulnerable to…
> This sort of objection is raised whenever basically any mechanism for remembering strong passwords is presented. Yes, because we've basically realized that memorizing passwords isn't a workable solution. We should be recommending password managers that generate/store strong passwords and MFA for any account that needs to be secure. That these password generators themselves can now be unlocked using both memorized i…
passwords are a flawed solution
They have been through history and way before the industrialized world, not only that but what was considered secure yesterday may be compromised today or tomorrow. This is not going away any time soon and you have to design security taking this into account.
Another problem with password, it's that those web services we use password for collect way too much sensitive information that they should not be given in the first place.
Re: A plastic card for easy to remember strong passwords
#85Earlier quoted context omitted.
There is no need to even break the codeword as it is the same for every site. In the above example say we want to guess their gmail password, it is probably: sh(/J3HqAfQsu.?u.?? We have only three characters to guess! OTOH this is only relevant for targeted attacks where the attacker has one password. This still protects you pretty well from bulk attacks (so long as the card is not widely used) and is miles better th…
The site is only an example. You would actually order your own unique card to carry with you. No one would be able to guess your password since your spacebar code is unique to your card.
Re: A plastic card for easy to remember strong passwords
#86This is a lot like PasswordCard[0] except not free. [0] https://www.passwordcard.org/en I think I'd like PasswordCard because it's pretty freeform - just pick a starting point and a visual direction/pattern and copy letters from the card. But honestly I don't much like the idea of relying on a physical token if I don't need to. Almost losing my 2FA last year was a bit scary.
PasswordCard does give you a seed number to generate the same card, though..
Qwertycard on the contrary exposes their recommended scheme publicly which make losing the card a much higher risk of compromising your password.
Re: A plastic card for easy to remember strong passwords
#87Except it's not going to work, because of the bank who doesn't allow '(' as a special character, or the ticket website that requires at least 3 digits, or the financial firm who only allows 8 character passwords. As soon as you have a few sites with 'rogue' password policies, the system breaks down.
Yeah, qwerty card are badly thought out, they know of the shortcomings and they don't care much as they're in this business for the money.
Re: A plastic card for easy to remember strong passwords
#88This would actually be very useful for my Google and LastPass password. I have everything else in my LastPass manager, but it is always trying to get into my google account from different places is difficult, so I have a rememberable password for both. This would let me keep a much more secure password for both.
Just use random words. Memorable passwords don’t have to be weak. Five random common english words are already very strong. Just make sure you don’t pick the words by hand.
Bruce Schneier blogged about this last year: https://www.schneier.com/blog/archives/2014/03/choosing_secu...
Re: A plastic card for easy to remember strong passwords
#89Earlier quoted context omitted.
This sort of objection is raised whenever basically any mechanism for remembering strong passwords is presented. Much like many results in computational complexity, worst-case results are not necessarily indicative of real-world utility. To wit, in the scenario you outlined the attacker must a) know beforehand that the target was using this device; b) know beforehand that the inserted middle portion was vulnerable to…
> This sort of objection is raised whenever basically any mechanism for remembering strong passwords is presented. Yes, because we've basically realized that memorizing passwords isn't a workable solution. We should be recommending password managers that generate/store strong passwords and MFA for any account that needs to be secure. That these password generators themselves can now be unlocked using both memorized i…
Correct analysis,
> recommend password managers
No! Passwords should never be considered as secure material, period. Centralizing in a password manager centralizes the burden. There are half a dozen other workable solutions, among which authentication by email (What else is the reset-by-email link?), Mozilla Persona and all kinds of asymetric keys.
Re: A plastic card for easy to remember strong passwords
#90If the end goal is to turn a long, comprehensible password like "correcthorsebatterystaple" into something not remotely subject to a dictionary attack, then merely shifting your fingers over on the keyboard by one key is much more convenient: "vpttrvyjptdrnsyyrtudys[;r". Sure, it suffers from the same short-comings as mentioned above (it's still a substitution cipher), but it's much more convenient than going to the…
I have used a similar variation in the past, in my case the character substitution came from changing the keymap of the keyboard.
for example 'correct' typed in qwerty over a dvorak keymap became 'krpp>ky'