BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] deadmanish login?
- Subject: [Discuss] deadmanish login?
- From: kentborg at borg.org (Kent Borg)
- Date: Fri, 3 Feb 2017 13:20:11 -0500
- In-reply-to: <d08d1f8f-e3ae-2e34-425e-83edf083780e@gmail.com>
- References: <iydoKFG1q6EvZNl6T2sztfNEyMK3eE7jp_2ZXrcPTgVFK1IPE5deLwZcViB_xDQMcb16enHDIBp9gek18AIxu5VrLtdgSHK6qEOO91dh2nA=@protonmail.com> <20170131014651.GA21915@newtao.randomstring.org> <1cca093a-2f5b-c105-0288-5f435c11104e@borg.org> <e94de5ff-7644-d501-ccb4-fd4a6b32ff7a@napc.com> <565bdd82-c70e-3e64-6786-63f9b8de12da@borg.org> <e480dec0-22f0-99be-dbc0-fa3f75ddd1fe@gmail.com> <a47bda52-ca1f-15ab-2f57-3ab5d1519a48@borg.org> <ecfa4f25-9416-ddcc-d92f-7979136fdf96@borg.org> <837eb7de-a956-c4bb-63f4-e1bcfa0e3861@gmail.com> <37fde12c-5572-a9e2-0525-fb37a8400691@borg.org> <5560cbeb-9a49-b959-c28a-44a3f0145d0f@gmail.com> <b261f072-dd42-b3e1-119e-3a380444a4dc@borg.org> <CA+h9Qs59TDWE22RJ561vrLs4J6JmNN9W6Tqg=9mPGTUy4E4KLQ@mail.gmail.com> <01da354a-066d-2c10-1e10-5780569627e5@borg.org> <d08d1f8f-e3ae-2e34-425e-83edf083780e@gmail.com>
On 02/03/2017 12:40 PM, Richard Pieri wrote: > On 2/3/2017 8:47 AM, Kent Borg wrote: >> I'll change it to 12-honey-denver-doctor then! >> >> No one will even guess that. > A dedicated Hashcat rig can "guess" it within 5 minutes. You are confusing (1) a password used as a password, and (2) a passphrase used for an encryption key. They are completely different. 1. A password with 32-bits of entropy is quite good: because there are limits to how fast any computer system will accept password attempts. 2. An encryption passphrase with anything much less than ~100-bits of entropy is weak: because there is no hard limit on how fast an attacker might try to crack it (buy more hardware, work in parallel). > Take a 2K word list. There are about 8 billion (2^33) possible > combinations of 3 words from this list. Add the 2 character prefixes and > you approach 2^40 possible combinations. Sounds like a lot but it's > still fewer than the entire DES keyspace (2^56). How random your > sequences are doesn't matter when the set of all possible sequences is > so weak. And none (none!) of that applies to a password, used as a password, and not recycled between different systems. You are talking about encryption key passphrases, and your logic is sound in that case. You are a proponent of ssh keys, right? And you encrypt yours, right? And you use a passphrase...that has how much entropy? I bet less than 100-bits of entropy, because typing good passphrases is really hard. I further bet that your key sits unencrypted much of the time because you are too lazy to type even your poor passphrase every time you would have to. Good passphrase hygiene is hard, much harder than good password hygiene. Compared to a decent password (that isn't shared between systems*) ssh keys solve a problem that doesn't exist, yet they create additional problems that you ignore. -kb * On not recycling passwords: Everyone does it, I assume you do, too. So if someone cracks into one system, yes they might crack into other systems sharing that password. Well, it is unfair to blame your secret password for the fact that you have been handing out copies of a password you should have been keeping secret. The fix for this problem is keep your password secret and not to recycle it between systems.
- Follow-Ups:
- [Discuss] deadmanish login?
- From: john at johnbyrnes.info (John Byrnes)
- [Discuss] deadmanish login?
- References:
- [Discuss] deadmanish login?
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] deadmanish login?
- From: kentborg at borg.org (Kent Borg)
- [Discuss] deadmanish login?
- From: kentborg at borg.org (Kent Borg)
- [Discuss] deadmanish login?
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] deadmanish login?
- From: kentborg at borg.org (Kent Borg)
- [Discuss] deadmanish login?
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] deadmanish login?
- From: kentborg at borg.org (Kent Borg)
- [Discuss] deadmanish login?
- From: jabr at blu.org (John Abreau)
- [Discuss] deadmanish login?
- From: kentborg at borg.org (Kent Borg)
- [Discuss] deadmanish login?
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] deadmanish login?
- Prev by Date: [Discuss] deadmanish login?
- Next by Date: [Discuss] deadmanish login?
- Previous by thread: [Discuss] deadmanish login?
- Next by thread: [Discuss] deadmanish login?
- Index(es):