Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month at the Massachusetts Institute of Technology, in Building E51.

BLU Discuss list archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] deadmanish login?

On Wed, Feb 1, 2017 at 12:03 PM, Richard Pieri <richard.pieri at> wrote:
> On 1/31/2017 8:48 AM, Kent Borg wrote:
>> "15-ladder-bamboo-sierra" is an easy password to remember and type, yet
>> it has 40-bits of entropy. Even if some bizarrely configured sshd
> It also uses dictionary words. Using dictionary words (read: not random)
> reduces the effective entropy of the key.

My quick estimate is that just the 3 words in his password gives him
something close to 40 bits.
That's assuming a dictionary size of 10000 words.

If you assume that an attacker has to do a rate-limited on-line attack
to search that 40bit space,
that seems adequate to me.  On the other hand, if you allow for the
possibility of an attacker
obtaining the password hash file and attacking it offline; then maybe
that isn't enough.
Kent's concern seems to be that because your SSH private key file is
encrypted, many people will
put it lots of places where they shouldn't.   If just one of those
places is compromised even briefly
the attacker can do an off-line attack against the key file.

Aside, since others have noted their non-standard security procedures...

I regularly reuse passwords between different systems.   Specifically,
systems/web sites in which I
have no significant stake.   I really don't care if someone who
manages to crack the InfoWorld web
site can then read the NY Times using the same credentials.   Each
financial and email account on the other
hand gets a different password.

Bill Bogstad

> --
> Rich P.
> _______________________________________________
> Discuss mailing list
> Discuss at

BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!

Boston Linux & Unix /