5 ms·
Sounds like if I were targeting your accounts specifically, I'd have a pretty easy time of it. As soon as I get hold of one or two of your passwords I can work
by katamole 18y ago
Sounds like if I were targeting your accounts specifically, I'd have a pretty easy time of it. As soon as I get hold of one or two of your passwords I can work out the algorithm and then start calculating your passwords myself.
While it might be a better approach than just using the same insecure password on every site, based on the attack suggested in this article, there isn't much benefit from your approach.
- tptacek 18y agoLuckily nobody is targeting his account specifically. The original point, that your low-value passwords can be harvested, is I guess well-taken. But you're pushing it.
- axod 18y agoif the algorithm is something like: password = sha1(masterpw1 + sitename + masterpw2) I'm not sure you can deduce masterpw1/2 from a few passwords.
- tjogin 18y agoI don't think you could work out the algorithm, because it's not mathematic. It's a handful of quirky arbitrary rules. But hey, give it a shot; here are three random passwords (calculated using a slightly different algorithm than the one i actually use): hotmail: 3m4m349 facebook: w45c033 aol: t41m325 Now, tell me what my Gmail password is.
- katamole 18y agoI would never try and second guess somebody who describes himself as "Devil's Advocate Extraordinaire."
- tjogin 18y agoI thought you said you'd have a "pretty easy time" figuring it out?
- jfornear 18y agois your hotmail password a typo? should it be m34m349?
- tjogin 18y agoNope. But it could have been if for a different service/purpose.