Overclock.net › Forums › Industry News › Technology and Science News › [Ars] Why passwords have never been weaker—and crackers have never been stronger
New Posts  All Forums:Forum Nav:

[Ars] Why passwords have never been weaker—and crackers have never been stronger - Page 4

post #31 of 49
Quote:
Originally Posted by ez12a View Post

KeePass generating a random 20 character passwords with symbols and numbers. Been using it increasingly over the past few days.

this, whenever I make a new account I simply use add and entry into KeePass and use the random generated password

cool thing is Chrome also by default has a password manager that saves it too (but you can't edit the saved password, only delete it)
    
CPUMotherboardGraphicsRAM
i5 3570K @ 4.6GHz Asus Sabertooth z77 Asus Radeon HD7970  Samsung Green MV-3V4G3D/US 8GB 2x4GB DDR3 1600MHZ 
Hard DriveHard DriveOptical DriveOS
OCZ Agility 3 240GB  Samsung F4 HD204UI LG Blu-Ray Burner CH08LS10 Windows 8 Pro 64 bit 
MonitorKeyboardPowerCase
HP LP2475w Filco Majestouch-2 Corsair HX850w Corsair Obsidian 800D 
MouseMouse PadAudio
Logitech G400 Artisan Hayate (Large) Asus Xonar Essence STX 
  hide details  
Reply
    
CPUMotherboardGraphicsRAM
i5 3570K @ 4.6GHz Asus Sabertooth z77 Asus Radeon HD7970  Samsung Green MV-3V4G3D/US 8GB 2x4GB DDR3 1600MHZ 
Hard DriveHard DriveOptical DriveOS
OCZ Agility 3 240GB  Samsung F4 HD204UI LG Blu-Ray Burner CH08LS10 Windows 8 Pro 64 bit 
MonitorKeyboardPowerCase
HP LP2475w Filco Majestouch-2 Corsair HX850w Corsair Obsidian 800D 
MouseMouse PadAudio
Logitech G400 Artisan Hayate (Large) Asus Xonar Essence STX 
  hide details  
Reply
post #32 of 49
Quote:
Originally Posted by RiverOfIce View Post

Using word phrase passwords is not really all the secure. Here is why. If I assume that you are using only English words and you spelled the correctly, I can crack that password in a few minutes.
Take the maximum number of characters allowed by the account. Take the minimum number of characters allowed by the account. For example, it can not be longer then 16 characters, or shorter then 6. Now you can take the common English dictionary combine each word that is shorter then 16 characters. You now have limited that possible words to less then 80,000 possible choices. Take all the words shorter then 6 characters and combine them words under 16 characters, you have less then 100,000,000 combos, I am rounding it here, it can not be less then 171,000 words nor more then 120 million combos.
If you take that the fact that you have limited the number of possible words and word orders to less then 100,000,000 combos, your password is broken in less then 10000 seconds. Which means that you have a password that is crack able in less then 27 days. Remove all uncommon words, remove all words that combo does not equal more then 16 and less then 6, you can crack it in less then 12 seconds.
Sorry, it is just not very secure.
The best way to make up passwords is to use a poem.
A Cliff Dwelling- Robert Frost
There sandy seems the golden sky
And golden seems the sandy plain.
No habitation meets the eye
Unless in the horizon rim,
Some halfway up the limestone wall,
That spot of black is not a stain
Or shadow, but a cavern hole,
Where someone used to climb and crawl
To rest from his besetting fears.
I see the callus on his soul
The disappearing last of him
And of his race starvation slim,
Oh years ago - ten thousand years.
TsstgsAgstspNhmte- would take 9 thousand centuries
Anyone can remember a song, poem, or favorite quote. Remember it is very simple and very easy to remember.
Using common words is insanely easy to break with brute force and is trip over easy to crack for rainbow tables. If you use the poem above, unsalted hashed passwords would take decades to crack. Unsalted whole word phrases will go down in minutes.

Add in capitals, numbers, and symbols and it's not that easy.

My password above, "blueman21isarabbit@thebox" would take 30.20 billion trillion centuries to crack at one-hundred trillion guesses per second. 9k centuries is nothing next to that. Using just lowercase and uppercase letters is probably the worst thing you can do. Just because you are using pre-made words doesn't make the pass any easier to crack. The person doing the cracking would have to know this and on top of that would have to know the character count.
Edited by Shrimpykins - 8/22/12 at 5:46am
 
Project Al
(69 photos)
 
CPUMotherboardGraphicsRAM
Intel 2700k Gigabyte UD4 MSI 580GTX Lightning Xtreme Edition 3GB 2x4GB G.Skill @ 1600mhz CL6 
Hard DriveHard DriveOptical DriveOS
OCZ Vertex II SSD OCZ Vertex II SSD LG Blu-Ray/HD-DVD Combo Drive Win 7 Ult 
MonitorMonitorKeyboardPower
Achieva Shimian Acer G235H XArmor U9BL Corsair HX1000W 
CaseMouseMouse PadAudio
Fractal Define R3 Silver Arrow Razer Naga Ultimate Razer Goliathus Speed Edition Polk Audio RTi-A1 
AudioAudio
Dayton Audio DTA-100a Asus Xonar STX 
  hide details  
Reply
 
Project Al
(69 photos)
 
CPUMotherboardGraphicsRAM
Intel 2700k Gigabyte UD4 MSI 580GTX Lightning Xtreme Edition 3GB 2x4GB G.Skill @ 1600mhz CL6 
Hard DriveHard DriveOptical DriveOS
OCZ Vertex II SSD OCZ Vertex II SSD LG Blu-Ray/HD-DVD Combo Drive Win 7 Ult 
MonitorMonitorKeyboardPower
Achieva Shimian Acer G235H XArmor U9BL Corsair HX1000W 
CaseMouseMouse PadAudio
Fractal Define R3 Silver Arrow Razer Naga Ultimate Razer Goliathus Speed Edition Polk Audio RTi-A1 
AudioAudio
Dayton Audio DTA-100a Asus Xonar STX 
  hide details  
Reply
post #33 of 49
Password in binary
My PC
(15 items)
 
 
ASRock Z77 Pro4 Review
ASRock Z77 Pro4 ATX Intel Motherboard
CPUMotherboardRAMHard Drive
AMD A6-3650 ASRock A55 Crucial Ballistix Sport Hitachi Travelstar 
OSMonitorKeyboardPower
Windows 7 Home Premium BenQ FP767 Inland PS/2 Tactile Corsair CX430W V2 
Case
Linkworld mATX Case 
  hide details  
Reply
My PC
(15 items)
 
 
ASRock Z77 Pro4 Review
ASRock Z77 Pro4 ATX Intel Motherboard
CPUMotherboardRAMHard Drive
AMD A6-3650 ASRock A55 Crucial Ballistix Sport Hitachi Travelstar 
OSMonitorKeyboardPower
Windows 7 Home Premium BenQ FP767 Inland PS/2 Tactile Corsair CX430W V2 
Case
Linkworld mATX Case 
  hide details  
Reply
post #34 of 49
Quote:
Originally Posted by nekon View Post

LastPass post-flame-small.gifthumb.gif

^^This^^

I use random generated Passwords for every account that i have and make them the maximum amount of characters possible.

Once i discovered Last Pass i went and changed every password for everything that i have to log into. lol

Everything is encrypted with Last Pass and makes it much more secure.

The other great thing about Last Pass is that it integrates with my Google Authenticator. I put in my master password and then it asks me to slap in a code from my Google authenticator as well.

http://helpdesk.lastpass.com/security-options/google-authenticator/
Edited by Ksireaper - 8/22/12 at 6:06am
Gaming Rig
(14 items)
 
  
CPUMotherboardGraphicsRAM
i7-930 EVGA X58 Sli LE XFX DD7950 3GB G.SKILL PI Series 6GB (3 x 2GB) 240-Pin DDR3 SDRAM 
Hard DriveOptical DriveOSMonitor
Crucial M4 128GB SSD Liteon dvd burner Windows 8  Dell UltraSharp U2410 - 24" 
KeyboardPowerCaseMouse
Xarmor U9BL Corsair HX 850 Antec 1200 Razer Naga 
Mouse PadAudio
Razer Destructor Razer Carcharias 
  hide details  
Reply
Gaming Rig
(14 items)
 
  
CPUMotherboardGraphicsRAM
i7-930 EVGA X58 Sli LE XFX DD7950 3GB G.SKILL PI Series 6GB (3 x 2GB) 240-Pin DDR3 SDRAM 
Hard DriveOptical DriveOSMonitor
Crucial M4 128GB SSD Liteon dvd burner Windows 8  Dell UltraSharp U2410 - 24" 
KeyboardPowerCaseMouse
Xarmor U9BL Corsair HX 850 Antec 1200 Razer Naga 
Mouse PadAudio
Razer Destructor Razer Carcharias 
  hide details  
Reply
post #35 of 49
Quote:
Originally Posted by Bobotheklown View Post


Quote:
This $12,000 computer, dubbed Project Erebus v2.5 by creator d3ad0ne, contains eight AMD Radeon HD7970 GPU cards. Running version 0.10 of oclHashcat-lite, it requires just 12 hours to brute force the entire keyspace for any eight-character password containing upper- or lower-case letters, digits or symbols. It aided Team Hashcat in winning this year's Crack Me If You Can contest.

I really need to get better passwords frown.gif

Just use a longer password. It takes 12 hours for an 8 character password, it will take about 900 hours for a 9 character password.

The solution to this is problem is actually simple. You get a password keychain/wallet program that has a complex password that you will never forget, and that is the only password you ever have to remember, and then the program remembers every other password for you. Then for all of the individual passwords that you use for different websites and accounts, use a very long (20 characters ought to do it) and completely randomized password, which is far too large to brute-force, and must be brute-forced because of its randomness.

EDIT: Looks like this has already been mentioned in this thread.
Foldatron
(17 items)
 
Mat
(10 items)
 
Work iMac
(9 items)
 
CPUMotherboardGraphicsGraphics
i7 950 EVGA x58 3-way SLI EVGA GTX 660ti GTX 275 
RAMHard DriveHard DriveHard Drive
3x2GB Corsair Dominator DDR3-1600 80GB Intel X25-M SSD 2TB WD Black 150GB WD Raptor 
Hard DriveOSMonitorKeyboard
2x 150GB WD V-raptor in RAID0 Win7 Home 64-bit OEM 55" LED 120hz 1080p Vizio MS Natural Ergonomic Keyboard 4000 
PowerCase
750W PC P&C Silencer CoolerMaster 690 
CPUGraphicsRAMHard Drive
Intel Core i5 2500S AMD 6770M 8GB (2x4GB) at 1333Mhz 1TB, 7200 rpm 
Optical DriveOSMonitorKeyboard
LG 8X Dual-Layer "SuperDrive" OS X Lion 27" iMac screen Mac wireless keyboard 
Mouse
Mac wireless mouse 
CPUGraphicsRAMHard Drive
i7-2600K AMD 6970M 1GB 16GB PC3-10600 DDR3 1TB 7200rpm 
Hard DriveOptical DriveOSMonitor
256GB SSD 8x DL "SuperDrive" OS X 10.7 Lion 27" 2560x1440 iMac display 
Monitor
27" Apple thunderbolt display 
  hide details  
Reply
Foldatron
(17 items)
 
Mat
(10 items)
 
Work iMac
(9 items)
 
CPUMotherboardGraphicsGraphics
i7 950 EVGA x58 3-way SLI EVGA GTX 660ti GTX 275 
RAMHard DriveHard DriveHard Drive
3x2GB Corsair Dominator DDR3-1600 80GB Intel X25-M SSD 2TB WD Black 150GB WD Raptor 
Hard DriveOSMonitorKeyboard
2x 150GB WD V-raptor in RAID0 Win7 Home 64-bit OEM 55" LED 120hz 1080p Vizio MS Natural Ergonomic Keyboard 4000 
PowerCase
750W PC P&C Silencer CoolerMaster 690 
CPUGraphicsRAMHard Drive
Intel Core i5 2500S AMD 6770M 8GB (2x4GB) at 1333Mhz 1TB, 7200 rpm 
Optical DriveOSMonitorKeyboard
LG 8X Dual-Layer "SuperDrive" OS X Lion 27" iMac screen Mac wireless keyboard 
Mouse
Mac wireless mouse 
CPUGraphicsRAMHard Drive
i7-2600K AMD 6970M 1GB 16GB PC3-10600 DDR3 1TB 7200rpm 
Hard DriveOptical DriveOSMonitor
256GB SSD 8x DL "SuperDrive" OS X 10.7 Lion 27" 2560x1440 iMac display 
Monitor
27" Apple thunderbolt display 
  hide details  
Reply
post #36 of 49
Quote:
Originally Posted by RiverOfIce View Post

Using word phrase passwords is not really all the secure

...

Using common words is insanely easy to break with brute force and is trip over easy to crack for rainbow tables. If you use the poem above, unsalted hashed passwords would take decades to crack. Unsalted whole word phrases will go down in minutes.

Add in a single random character to said common word password and it is no longer possible to to break a word phrase password in the fashion you describe.
post #37 of 49
Because of this thread i jumped and bough 1 year of LastPass wink.gif
LGA2011
(12 items)
 
  
CPUMotherboardGraphicsRAM
Intel Core i7 3930k ASUS Rampage IV Extreme EVGA GTX680 Classified 4GB Corsair Dominator Platinum 16GB 2133Mhz 
Hard DriveCoolingOSMonitor
Samsung 830 256GB Corsair H100 Windows 7 x64 Pro SP1 Samsung SyncMaster 2493HM 
KeyboardPowerCaseMouse
Saitek Corsair AX850 Corsair 800D Logitech 
  hide details  
Reply
LGA2011
(12 items)
 
  
CPUMotherboardGraphicsRAM
Intel Core i7 3930k ASUS Rampage IV Extreme EVGA GTX680 Classified 4GB Corsair Dominator Platinum 16GB 2133Mhz 
Hard DriveCoolingOSMonitor
Samsung 830 256GB Corsair H100 Windows 7 x64 Pro SP1 Samsung SyncMaster 2493HM 
KeyboardPowerCaseMouse
Saitek Corsair AX850 Corsair 800D Logitech 
  hide details  
Reply
post #38 of 49
Quote:
Originally Posted by Orici View Post

Because of this thread i jumped and bough 1 year of LastPass wink.gif

I did also along with the Yubikey :d
post #39 of 49
Quote:
Originally Posted by Zen00 View Post

Why passwords have never been weaker—and crackers have never been stronger
My password has yet to be compromised, but one day... Guess I better make a set of extra passwords for the day.

I use junk passwords for stuff that isn't important and 16-32 length logins in multiple languages on important stuff. 99% of the time crackers are only using ENGLISH decryption so it will get them every time tongue.gif I use to know a guy who liked to get free logins to adult websites and he showed me a few ways to lower my chances of being a victim of it lol.


Also a small tip, if you plan to ditch a website then change your login to something different then your main logins. That site you ditch might sell the logins or a backup gets leaked etc and then they have your login combo and can test sites using it. Most "crackers" aren't a issue but the real hackers that are, they will use programs like triton to backdoor the websites and steal the encryption key + login file for a easy decryption of the logins as well.
Edited by Twist86 - 8/22/12 at 7:22pm
    
CPUMotherboardGraphicsRAM
Q6600 GIGABYTE GA-EP45-UD3R (rev. 1.0) XFX GTX 260 868mb 192 Core 2x2GB G-skill PC6400 DDR2 800 
Hard DriveOSMonitorKeyboard
Western Digital Caviar Black WD5001AALS Windows 7 x64 1680x1050 Acer X223w 22" Logitech G11 
PowerCaseMouseMouse Pad
TX750w Corsair PSU Antec 900 Logitec MX-518 WoW Catclysm 
  hide details  
Reply
    
CPUMotherboardGraphicsRAM
Q6600 GIGABYTE GA-EP45-UD3R (rev. 1.0) XFX GTX 260 868mb 192 Core 2x2GB G-skill PC6400 DDR2 800 
Hard DriveOSMonitorKeyboard
Western Digital Caviar Black WD5001AALS Windows 7 x64 1680x1050 Acer X223w 22" Logitech G11 
PowerCaseMouseMouse Pad
TX750w Corsair PSU Antec 900 Logitec MX-518 WoW Catclysm 
  hide details  
Reply
post #40 of 49
Quote:
Originally Posted by Orici View Post

Because of this thread i jumped and bough 1 year of LastPass wink.gif

You know last pass is free, right? Unless you run it on your mobile devices.

But I use it for Chrome on my desktop computer, USB Portable Apps version, and on my laptop. Once i get me a smartphone I will be purchasing a subscription too. I also use xmarks to keep my bookmarks synchronized. Honestly, I don't know the password to anything but my lastpass account. I am helpless without it.
New Posts  All Forums:Forum Nav:
  Return Home
  Back to Forum: Technology and Science News
Overclock.net › Forums › Industry News › Technology and Science News › [Ars] Why passwords have never been weaker—and crackers have never been stronger