9 ms·
Lessons from a Professional Password Cracker
- lawgimenez 4y ago> Another legitimate case for password cracking is if someone in accounting encrypted a spreadsheet and then got hit by a bus and other employees needed access to that document Ah the good ol' bus factor.
- bloaf 4y agoI love that Nation States uses the "Bus Surprisal Index" as the measure of unexpected death rate. https://nationstates.fandom.com/wiki/World_Census https://nationstates.fandom.com/wiki/World_Census
- aljgz 4y agoDon't choose password to make offline cracking hard. Sounds exactly like the advice an offline cracker would give. ;)
- richrichardsson 4y agoSlightly off topic but it made me smile: The linked Diceware website run by the daughter has press links about the $2 passwords she sells. The FAQ notes the passwords are $4 a pop. The actual price: $8
- dankwizard 4y agoI feel now is the time to shill my free cloud, 18-character length password generator [1]. It is a completely serious password generator only requiring a Twitter mention (@) to summon. Paid premium extends this to 21 characters. 1: https://twitter.com/generatepw https://twitter.com/generatepw
- asyncscrum 4y agoThe rockyou.com insight was new to me. I hadn't heard of this breach somehow. I was wondering how they had 32m users and read some more on Wikipedia and they had Facebook apps and some MySpace plugins. From Wikipedia > In December 2009, RockYou experienced a data breach resulting in the exposure of over 32 million user accounts. This resulted from storing user data in an unencrypted database (including user passwords in plain text instead of using a cryptographic hash) and not patching a ten-year-old SQL vulnerability. RockYou failed to provide a notification of the breach to users and miscommunicated the extent of the breach
- capableweb 4y agoFun fact: rockyou.txt by now is probably one of the most common/famous wordlists out there, used for doing various types of dictionary attacks and the entire list ships by default with lots of tools, including Kali Linux which is a common distribution for pentesting.
- lucb1e 4y ago> one of the most common/famous wordlists out there, used for doing various types of dictionary attacks and the entire list ships by default with lots of tools Famous, ships by default, agree, but actually used? It's really low quality, I've mostly seen it used for CTFs: because it is so common, the organizers / challenge makers think picking a password from this list is fair game for a challenge where the trick is to crack some user password hash without requiring proper cracking hardware. In the real world, it can be a starting point but it's not really used much anymore. Things like the linkedin list and newer lists are more accurate, especially when combined with rule sets that add additional transformations (add an(other) exclamation mark to a password, change o to zero, combinations of these things, etc.)
- WalterBright 4y agoI use this password for all my accounts: BingoBongo77. Is it secure? Edit: oh crap
- arthurcolle 4y agoDon't worry, all I can see is ••••••••••••. The browser builds in technology so that it conveniently shows you your password (BingoBingo77), but all I can see is ••••••••••••. Neat, right?
- WalterBright 4y agoPhew!
- maxbond 4y agoThanks for the smile, strangers. For anyone out of the loop: http://www.bash.org/?244321 http://www.bash.org/?244321
- hunter2_ 4y agoClassic
- thunkle 4y agoHa. Did you make your name for this comment?
- lucb1e 4y agoEvidently not https://news.ycombinator.com/threads?id=hunter2_&next=10686621 https://news.ycombinator.com/threads?id=hunter2_&next=106866...
- arthurcolle 4y ago
- jiggawatts 4y agoSome rules of thumb: All Windows passwords shorter than about 10 characters shouldn't be considered secure, as the NT Hash at this point is so easily reversible that it's basically a "light obfuscation" at best. A single GPU can crack all 8-character passwords in minutes. The single best security setting on a Windows network is to increase the minimum password length to something like 14 characters. Use 20+ for privileged or service accounts. The second best thing to do is to scan password hashes against "top password" lists and reject any that are in the top-N, where its up to your business policy what 'N' is. I recommend at least the top 10,000 most common passwords being outright rejected. The third thing is to match against specific leaks. E.g.: if you have john.smith@foo.com and there is a leak of his email and password where the password matches your records, force a password change immediately. All of the above assumes that MFA is in place, your servers are patched, and there are extensive audit logs on all authentication attempts.
- macintux 4y agoSomething I’ve wished companies would do: publish (on an internal site) all of their employees’ previous passwords each time they’re rotated. Users would be compelled to create better passwords out of sheer embarrassment/competitive spirit.
- arjvik 4y agoPlus, it would mean people would stop just incrementing a number at the end if it revealed their pattern.
- exhilaration 4y agoIf companies want us to stop incrementing a number (guilty!) or writing our passwords on post-its stuck on our monitors, they should stop requiring us to change our passwords every freaking month. I think it was only in 2021 that NIST suggested the password change frequency should be yearly.
- amlozano 4y ago
- hamiltonians 4y agomeh. pro hackers do not crack or bruteforce passwords except as a last resort. they instead find some critical vulnerability that bypasses the need for passwords, or steal the browser sesion, or use malware. this is how so many people got crypto stolen despite strong passwords.
- SamBam 4y agoThis is the point of TFA.
- nimbius 4y agoshameless plug: the EFF sells a dice set and fun sticker for use with their wordlist. https://www.eff.org/dice https://www.eff.org/dice
- kadoban 4y agoNice. Seems to be a real improvement over diceware. > We manually checked and attempted to remove as many profane, insulting, sensitive, or emotionally-charged words as possible, and also filtered based on several public lists of vulgar English words I kind of wish they had a list _without_ this step though. Vulgar and emotionally charged words are easy to work into stories and easy to remember.
- deleted 4y ago[deleted]
- gmane 4y agoHey, I keep seeing people claim biometrics somehow fix the password problem, but I feel like this is just a password you can't change? I can't change my fingerprints nor my retina, but if that data ever gets leaked, then that's vulnerable forever? In my mind, there's no world where one could make a biometric scanner that couldn't be spoofed (presumably with an arduino USB interface) and then when all these corporations with the worst security (Facebook, Experian, etc) leak my data, can't anyone log into my account?
- deleted 4y ago[deleted]
- astrange 4y agoiPhone biometrics can’t be faked because the sensors can’t be moved between devices, each Face ID sensor uses a different random pattern, etc. It’s also more secure than a password on a phone because if you’re using it in public someone can watch you type your password in. Of course, someone might be able to clone your head shape.
- yosamino 4y ago> Of course, someone might be able to clone your head shape. This is from 2005: > Police in Malaysia are hunting for members of a violent gang who chopped off a car owner's finger to get round the vehicle's hi-tech security system. http://news.bbc.co.uk/2/hi/asia-pacific/4396831.stm http://news.bbc.co.uk/2/hi/asia-pacific/4396831.stm I guess this is a question of threat model. I hope nobody would want to chop of my head just to unlock my iphone. But this always reminds me of the scene in "Demolition Man" where Wesley Snipes spoons out someone's eyeball to open the biometrically locked door of his prison.
- lucb1e 4y agoWhat I'm hearing you say is that the hardware has baked-in private keys. That is not biometrics, that's public-private key authentication. People already do this with ssh/pgp private keys on a hardware token. Which is a good idea, but it has nothing to do with biometrics and is not something you need to sell your soul to apple for. > It’s also more secure than a password on a phone because if you’re using it in public someone can watch you type your password in. I'd rather hold a hand over a PIN pad than having to wear a mask to prevent my face from being scanned in public.
- hn_throwaway_99 4y ago> Instead of passwords, we should use something like FIDO, which allows users to log in using a security key or biometric information. The problem "in the real world" is that people will lose these keys all the time. I mean, I agree, passwords need to die, and hopefully some of the work that is being done by Apple and others will help bring on an end to passwords, but you can't really talk about replacing passwords with FIDO keys without talking about how to deal with account lockouts, which is a real, hard problem. Similarly, biometrics may be good for a user ID but they make horrible passwords. These days fingerprints and irises can be copied from photographs.
- bluedino 4y agoWe have the following: Authenticator app, HID card, or FIDO key. Biometric is coming but the goal is to not have to give people yet another reader/device. In theory we wouldn't have to worry about someone losing their card or key but they don't always setup all three in their account.
- tsimionescu 4y agoAre these used in conjuction, or any one will do? If it's the former, it seems like it would make the problem of loss worse. If it's the latter, then it seems you've offered a variety of ways that someone can access your systems - steal a key, copy biometrics, guess the phone password etc. - the weakest one will do.
- bluedino 4y agoYou only need to use one. You need a PIN to use any of the devices as well.
- hn_throwaway_99 4y agoOnly needing one means you have the "lowest common denominator" of 2FA. E.g. authenticator apps are vulnerable to phishing, while FIDO keys are not. Adding FIDO key as an optional second factor doesn't really add much security if people can still be phished using a MITM attack using the authenticator TOTP.
- mLuby 4y agoI'm surprised a password cracker would advocate switching to biometrics, the one type of password you can't change.
- lbriner 4y agoThat's not quite the case. Things like FIDO Yubikey are basically a password unlocked by biometric information so someone needs the key AND your biometric information to unlock it. Even if someone knew your "biometric" information, they would still need the key.
- lucb1e 4y agoAs someone also in this business, I would speculate that they give such advice because it is currently effective. It's hard to say whether that will remain the case when biometrics are more widely used. Perhaps, then, we find that storing hashes of all sorts of biometrics server-side is not such a good idea after all. Or if done client-side, then you basically have public key authentication which also exists today and is often recommended for things like ssh -- don't need biometrics for that, how you unlock your ssh key is up to you.
- Nextgrid 4y agoMost modern biometric auth is implemented by the biometric device acting as an HSM and only agreeing to perform the cryptographic operation with its secrets if the proper biometrics are provided. Biometrics are never directly sent to the service you're authenticating to, instead it's using a form of PKI in the background where your biometric device is an HSM storing the client certificate. This is less secure against dedicated attackers with physical access, but much more secure against remote attackers as there's usually no way to provide the biometrics to the HSM in software and the authentication key from the biometric device can't be stolen so you must keep persistent access to it to be able to use it every time you need to authenticate.
- Eleison23 4y agoI've really embraced biometrics now that I understand that they're effective for certain use-cases when properly implemented. For example, the primary threat model for my mobile device is a combination of shoulder-surfing and theft, because I ride a lot of public transit. So it's way more secure for me to touch the fingerprint sensor rather than constantly peck in my password while I'm being observed. A common criminal or homeless dude who steals/finds my phone won't know my password because I'm not revealing it, and they're unlikely to have access to my finger or its print. If my threat model were different, say law enforcement/TSA confiscation or something, I might be more worried about walking around with fingerprint auth enabled. So if I head to the airport or enter some other high-risk area, I might consider disabling that, removing the sdcard and/or SIM card temporarily. Biometrics as a way for my personal device to recognize my physical presence is mature tech, and useful for consumers in ways that passwords aren't.
- lofaszvanitt 4y agoYubikey is here since 2007... and Windows 10 still doesn't support passwordless, security key only! login. They want you to register a goddamn MS account too...
- zokier 4y agoWindows has supported smartcard logins since at least 2000, should work fine with yubikeys too. https://support.yubico.com/hc/en-us/articles/360013707820-YubiKey-Smart-Card-Deployment-Guide https://support.yubico.com/hc/en-us/articles/360013707820-Yu...
- lofaszvanitt 4y agoYou need an additional MS account for login... no it doesn't work in ITSELF.
- Eleison23 4y agoMicrosoft Outlook and live.com logins can use security keys, in fact they are accepted as a single authentication factor rather than a second one: supply your Yubikey and you're logged in without username or password! However, Windows Hello in Windows 10 does not support local logins with security keys. This may have changed last week with a recent update, but it definitely wasn't supported when I installed Windows last Christmas. I think it's Microsoft's opinion that security keys are too secure for consumer use; if a consumer is locked out of their personal device due to mismanagement, theft or loss of a hardware key, that's a support headache and liability burden that they're unwilling to take on at this point.
- iamcrazyyounus 4y agoDoes this hold true even after the removal of LM hash v1 support?
- upofadown 4y agoThis all comes down to this statement: >In fact, pretty much the only case where complexity and length matter is when we’re defending against offline password cracking. But for every other case in the threat model where passwords are stolen, length and complexity simply don’t matter. The idea is that most passwords are stolen when they are plaintext. So it only matters that the password is unique to that system. Offline password cracking is relevant for cases like the passphrase used to protect your PGP or SSH keys. Then length and complexity is important. Stuff like the suggested FIDO is the same sort of thing. If you need to protect the FIDO key information then length and complexity of your passphrase is important where offline password cracking is relevant.
- imwillofficial 4y ago“A series of dictionary words that is easy for me to remember but hard gif a computer to crack” facepalm
- btbuildem 4y agoMeanwhile banks and large corps still enforce the inane "minimum of 8 characters, must contain at least one symbol and one number" password template.
- GoblinSlayer 4y agoConsider yourself lucky if it's not "maximum of 8 characters".
- slowhand09 4y agoYou're telling me ROT13 isn't enough..?
- zekrioca 4y ago> I started paying her to roll dice and make Diceware passwords for me. Interesting way to incentivize their daughter to do something.