Live data from Hacker News

A plastic card for easy to remember strong passwords

qwertycards.com

81–90 of 110 posts

Re: A plastic card for easy to remember strong passwords

#81
post #18

Except it's not going to work, because of the bank who doesn't allow '(' as a special character, or the ticket website that requires at least 3 digits, or the financial firm who only allows 8 character passwords. As soon as you have a few sites with 'rogue' password policies, the system breaks down.

I tried going to a similar algorithm of my own invention some years ago, and ran into this exact problem. Mostly sites that don't allow certain characters (which is asinine). Now I have a few different algorithms that I use that are friendly to common password requirements, and I keep a list of which algorithm I used on each website, rather than just a list of the passwords. Since the algorithms only exist in my head, I think it's secure enough for most purposes.

Re: A plastic card for easy to remember strong passwords

#83
post #7

This is a substitution cipher and it's not very secure. Consider what we can do if we compromise the Amazon password that's given as an example on the website: sh(/J3HqAfQsu..u.rqf Since the password came from Amazon, we know that the last 6 characters are "Amazon," which tells us that: . = A u = M r = Z q = O f = N Now we can start attacking the codeword, which are the characters between the 8-character "space bar c…

This sort of objection is raised whenever basically any mechanism for remembering strong passwords is presented. Much like many results in computational complexity, worst-case results are not necessarily indicative of real-world utility. To wit, in the scenario you outlined the attacker must a) know beforehand that the target was using this device; b) know beforehand that the inserted middle portion was vulnerable to…

Please do apply this sort of objection to a password card[1].

Then again there are different kinds of attack on passwords, among those is the dedicated targeted attack and those will be happy to exploit the false sense of security you get from a qwerty card.

Now if you want a practical alternative for choosing passwords you can remember: https://www.schneier.com/blog/archives/2014/03/choosing_secu...

Lastly using the same password for everything is wrong, but reusing a password for services that do not require a high level of security is acceptable such as posting comment on weblogs. bugmenot being a popular choice reminding of a time when their website was actually useful.

[1]https://www.passwordcard.org/

Re: A plastic card for easy to remember strong passwords

#84
post #30

Earlier quoted context omitted.

This sort of objection is raised whenever basically any mechanism for remembering strong passwords is presented. Much like many results in computational complexity, worst-case results are not necessarily indicative of real-world utility. To wit, in the scenario you outlined the attacker must a) know beforehand that the target was using this device; b) know beforehand that the inserted middle portion was vulnerable to…

> This sort of objection is raised whenever basically any mechanism for remembering strong passwords is presented. Yes, because we've basically realized that memorizing passwords isn't a workable solution. We should be recommending password managers that generate/store strong passwords and MFA for any account that needs to be secure. That these password generators themselves can now be unlocked using both memorized i…

I'll go even a step further and say:

passwords are a flawed solution

They have been through history and way before the industrialized world, not only that but what was considered secure yesterday may be compromised today or tomorrow. This is not going away any time soon and you have to design security taking this into account.

Another problem with password, it's that those web services we use password for collect way too much sensitive information that they should not be given in the first place.

Re: A plastic card for easy to remember strong passwords

#85

Earlier quoted context omitted.

There is no need to even break the codeword as it is the same for every site. In the above example say we want to guess their gmail password, it is probably: sh(/J3HqAfQsu.?u.?? We have only three characters to guess! OTOH this is only relevant for targeted attacks where the attacker has one password. This still protects you pretty well from bulk attacks (so long as the card is not widely used) and is miles better th…

The site is only an example. You would actually order your own unique card to carry with you. No one would be able to guess your password since your spacebar code is unique to your card.

This is wishful thinking, factor in the actual organization doing global surveillance and spying, say NSA who is known to intercept hardware to flash firmware with backdoors and suddenly the need to guess is no more, your card can be legally copied at any point between production or transportation to you.

Re: A plastic card for easy to remember strong passwords

#86
post #38
post #8

This is a lot like PasswordCard[0] except not free. [0] https://www.passwordcard.org/en I think I'd like PasswordCard because it's pretty freeform - just pick a starting point and a visual direction/pattern and copy letters from the card. But honestly I don't much like the idea of relying on a physical token if I don't need to. Almost losing my 2FA last year was a bit scary.

PasswordCard does give you a seed number to generate the same card, though..

Which is not really a problem because having the card does not give away the scheme used for a particular password.

Qwertycard on the contrary exposes their recommended scheme publicly which make losing the card a much higher risk of compromising your password.

Re: A plastic card for easy to remember strong passwords

#87
post #18

Except it's not going to work, because of the bank who doesn't allow '(' as a special character, or the ticket website that requires at least 3 digits, or the financial firm who only allows 8 character passwords. As soon as you have a few sites with 'rogue' password policies, the system breaks down.

Nah man, don't sweat it this case is thoroughly covered in their faq: you can petition those firms by tweeting them with #strongpasswords hashtag and @qwertycards.

Yeah, qwerty card are badly thought out, they know of the shortcomings and they don't care much as they're in this business for the money.

Re: A plastic card for easy to remember strong passwords

#88
post #5

This would actually be very useful for my Google and LastPass password. I have everything else in my LastPass manager, but it is always trying to get into my google account from different places is difficult, so I have a rememberable password for both. This would let me keep a much more secure password for both.

Just use random words. Memorable passwords don’t have to be weak. Five random common english words are already very strong. Just make sure you don’t pick the words by hand.

Except this has stopped being strong a while ago, since it has been popularized by xkcd in 2011 cracker have incorporated this scheme in their password cracking routines.

Bruce Schneier blogged about this last year: https://www.schneier.com/blog/archives/2014/03/choosing_secu...

Re: A plastic card for easy to remember strong passwords

#89
post #30

Earlier quoted context omitted.

This sort of objection is raised whenever basically any mechanism for remembering strong passwords is presented. Much like many results in computational complexity, worst-case results are not necessarily indicative of real-world utility. To wit, in the scenario you outlined the attacker must a) know beforehand that the target was using this device; b) know beforehand that the inserted middle portion was vulnerable to…

> This sort of objection is raised whenever basically any mechanism for remembering strong passwords is presented. Yes, because we've basically realized that memorizing passwords isn't a workable solution. We should be recommending password managers that generate/store strong passwords and MFA for any account that needs to be secure. That these password generators themselves can now be unlocked using both memorized i…

> Memorizing passwords isn't a workable solution

Correct analysis,

> recommend password managers

No! Passwords should never be considered as secure material, period. Centralizing in a password manager centralizes the burden. There are half a dozen other workable solutions, among which authentication by email (What else is the reset-by-email link?), Mozilla Persona and all kinds of asymetric keys.

Re: A plastic card for easy to remember strong passwords

#90

If the end goal is to turn a long, comprehensible password like "correcthorsebatterystaple" into something not remotely subject to a dictionary attack, then merely shifting your fingers over on the keyboard by one key is much more convenient: "vpttrvyjptdrnsyyrtudys[;r". Sure, it suffers from the same short-comings as mentioned above (it's still a substitution cipher), but it's much more convenient than going to the…

This is a simple variation that I have not seen covered in hashcat, though it is not future proof. If people catch on this then it won't be long before a new rule is added to hashcat to cover this case.

I have used a similar variation in the past, in my case the character substitution came from changing the keymap of the keyboard.

for example 'correct' typed in qwerty over a dvorak keymap became 'krpp>ky'

Post reply on HN