password, strong, strength, haystack, brute force, attack, hackers, id theft, guessing, cracking, array, steve gibson, security now, podcast
You are not logged in. Access is limited. Login or see membership information. • Streetwise Security Zone Community
You Must Be Logged In
You must be a member of this group and logged in to rate this post. Please see the links above on joining this group and/or logging in.

To see the list of all blogs, including Scott Wright's Security Views Blog and the Streetwise Security Zone Podcast click HERE. You also can subscribe via an RSS reader, or check the "Watch This" box in the left column to receive news by email of new articles.


Watch this Blog Notify me by e-mail any time a new post is made to this blog.

Scott Wright's editorials on a variety of security issues for non-technical business managers and home computer users. Please feel free to comment and help spread the word that managers need to think about their information security risks.

June 2011 Posts

Archives

  Scott Wright's Security Views
Blog Entry

How to easily create a much stronger password than you need to thwart a brute force attack

Tuesday, June 7th 2011 @ 8:14 PM (not yet rated)    post viewed 12725 times

If you have been struggling with the problem of how to keep passwords strong, yet memorable, we may have a simple answer for you. In the Security Now Podcast (episode 303) this week, Steve Gibson presents a very interesting analysis on what makes a good password these days. He calls it Password Haystacks, and there is a pretty simple solution to having to remember strong passwords.

Steve's conclusions are very compatible with my usual prefered strategy for choosing passwords - like using the first characters from a song or movie quote, and adding some special characters and numbers. But his advice is interesting about how simple the basic password root can be, and how to easily make it much stronger. It's pretty cool and simple.

The bottom line is that by adding length to a good, short password (regardless of whether or not they are repeated characters or patterns) you will massively improve resistance to a brute force attack. This is because today's attacker doesn't know how long the password is, for sure, and will always start with the easy dictionary words and patterns, and then they will move to the shortest possible character combinations in a brute force attack, followed by the next shortest combinations, and so on... 

As an example, using this logic, a 23 character random password is not "usefully" stronger than a 3 character random password with 21 repeated characters. 

There are some minor caveats in using this approach, to keep the passwords strong, such as having at least one lower, one upper case, one number and one special character in the root of the password. The rest of the characters don't really matter, as long as you don't reveal what pattern you use in the repeated characters or patterns.

For example "..B.o.B.........." is a pretty good password, since it would take at least 2 billion centuries with massive cracking array scenario to go through all combinations. So, you don't need a very long song title or movie phrase. You simply need to keep your simple pattern or strategy a secret.

The Security Now podcast episode (in text or audio format) where the rationale for this approach is described is at the following link:

http://www.grc.com/securitynow.htm (look for Episode 303)

Steve also has a web page that analyzes passwords in terms of how long a given password can be expected to stand up to various brute force attacks. You don't have to enter your real password, but try entering something that has the same length, and number of upper, lower case, numbers and special characters as your real password, and see how long it would take an attacker to try all combinations using a brute force approach.

http://www.grc.com/haystack.htm

If you aren't convinced, or if you want to learn more, post a question or comment below.

Something to ponder...

- Scott

If your organization is looking for innovative, cost-effective security awareness tools or training, please call or email me at the coordinates below; or CLICK HERE to learn more about Streetwise Security Awareness solutions.

Scott Wright

The Streetwise Security Coach

Join the Streetwise Security Zone at:
http://www.streetwise-security-zone.com/join.html

Phone: 1-613-693-0997
Email: scott@streetwise-security-zone.com
Twitter ID: http://www.twitter.com/streetsec

To receive weekly security tips and other notices about helpful content available on this site, please make sure you are on my list by clicking HERE, and entering your name and email address.

 

Site Meter

 rate this post: very bad poor average good fantastic!
Comments

Copyright 2012. Security Perspectives Inc. All Rights Reserved.