Online Passwords - 夜莺博客

Online Passwords

原文:Online Passwords — theDXT (Daniel Keer)

Recently some major password database leaks have been making headlines all over the internet.

Image 1: password

Last.fmthe social music website,LinkedIna professional social networking website, andeHarmonya well known dating website have all been victims of a recent cyber-crime spree of database break-ins. LinkedIn in particular is reporting that more than 8 million passwords may have been compromised.

Your passwords are essentially a digital fingerprint that could potentially lead to far greater security risks than most people realize. Someone for instance, with access to your linked in account, can have enough personal and professional information at their disposal to order credit cards in your name, use your identity to commit fraud, and many other nefarious things.

One of the most surprising and worrying things about these break ins however is not just the data that has been compromised; but also what passwords people have been using.

In an era where more and more of our lives are deposited online and tight security is needed to safeguard our identities, lives, and even children; passwords need to be at the very least difficult to guess. But thanks to the password leak, we’re now finding out people are still using passwords that are both extraordinarily dangerous, and easy to guess.

Passwords for LinkedIn, as an example, that were used often for many users were “12345”, “linkedinpassword” “iwantanewjob” and others according to an article fromArs Technica.

Why are they dangerous? Even if you don’t keep anything more than your email address and name on these website, that is more than enough for scam artists and fraud specialists to begin worming their way into your digital life using social engineering and basic psychology. The weakest link in any security system is the humans that control it, and with a convincing enough story and enough background information, any system can be breached.

Note: this post was first published in 2012. It has been expanded with the background, the arithmetic and the guidance that has changed since.

Password Hygiene: The Basics

So in light of this new information, we would like to offer some tips on how to keep your online life secure.

  1. Use a different password for each account.This way if a password database gets leaked on the internet you only have to change 1 password.
  2. Use a long password. The longer the password the longer it will take for someone to crack your password.
  3. Use lower case and upper case letter, symbols and numbers. It is much harder from someone to crack a password that is not just text. If a 2 character password only has letters that means there is only 676 different possibilities for your password to be but if you have a password with a number in it then there is 1296 different possibilities.
  4. Make sure you have a way to reset your password. If your like me your going to have to remember many different password, so it is likely that you will forget one sooner or later. Ensuring you have a way to reset your password will ensure that you will always have access to your account.

For even more information, Google has a good article about picking strong passwords. You can read it athttp://www.google.com/goodtoknow/online-safety/passwords/

Google's Good to Know guidance has since been largely superseded by the current NIST password recommendations and by the built in checks in modern browsers and password managers, both of which are covered above.

What Those Breaches Actually Taught Us

Looking back at the summer of 2012, the interesting part is not that three websites were breached. It is what the leaked data revealed about how sites stored passwords and how people chose them, and both findings are still shaping security advice today.

  • The hashing was the real story. LinkedIn stored its password database as unsalted SHA-1 hashes. Because the same password always produces the same hash without a salt, cracking one hash gave an attacker the password for every account that used it, and identical hashes could be spotted instantly in the dump. The figure quoted at the time was a few million hashes and, as the original post above notes, more than eight million passwords were said to be affected. When the same data set resurfaced four years later it turned out to cover roughly 117 million accounts, which is a useful reminder that early breach estimates are almost always too low.
  • Reuse did the damage. A leaked password is only a problem on the site it was leaked from, unless the same password is used somewhere else. Then it is a problem everywhere. The stolen user and password pairs were fed into automated tools that tried them against mail providers, social networks, banks and remote access gateways, a technique now called credential stuffing.
  • People chose predictable passwords. The most common entries in those leaks were variations of the site name, simple sequences and dictionary words, exactly the patterns the original tips in this post warn against. Rules that force a capital letter and a number did not fix that either, they just produced predictable mangling such as P@ssw0rd.

Years on, the same three lessons keep showing up in every large credential dump, but the attacker tooling is faster, the lists of known passwords are bigger, and defenders now have better options than complexity rules.

How Passwords Are Cracked

It is worth being precise about the threat, because it decides which advice actually helps. There are two very different attack models.

Online guessing is what happens at a login form. The site can rate limit it, lock the account, add a delay or require a second factor, so an attacker gets maybe a few dozen attempts before being stopped. Defences against online guessing are mostly on the service side, and MFA ends this attack outright for a well built service.

Offline cracking is what happens after a database is stolen. The attacker has the hashes and can test candidate passwords against them on their own hardware, with no rate limit at all. This is where password strength genuinely matters, and where the way a site hashes passwords decides how much strength you need.

A few techniques cover almost all offline cracking:

  • Dictionary and rule attacks. Start from a wordlist of real passwords leaked from previous breaches, then apply mangling rules: capitalise the first letter, append a digit, swap a for @, append the current year. Because the rules mirror what humans do, they find far more passwords per guess than pure brute force.
  • Brute force over the keyspace. Enumerate every possible password of a given length from a given character set. This is the attack the original tips in this post were aimed at.
  • Rainbow tables. Precomputed hash lookups that trade storage for speed. A per-site salt makes them useless, which is why salting every password with a unique random value is the single most important thing a site can do.
  • Credential stuffing. Not cracking at all, simply replaying passwords that are already known to work elsewhere.

The speed of offline cracking depends entirely on the hashing algorithm. A general purpose hash such as MD5 or SHA-1, which is what a lot of 2012 era sites used, can be tested at tens of billions of candidates per second on a small cluster of graphics cards. A deliberately slow password hash such as bcrypt, scrypt or Argon2 with a sensible cost factor brings that down to thousands or tens of thousands per second, which is a difference of roughly a million times in the attacker's favour or against.

The table below puts the keyspace of a few example passwords next to those two speeds. Treat the numbers as illustrative rather than exact, they depend on the hardware and on the cost factor, but the orders of magnitude are what matter:

Example password Character set and length Possible combinations At 10 billion guesses per second (unsalted MD5) At 10 thousand guesses per second (bcrypt)
abcdefgh 26 lower case, 8 characters 2.1 x 10^11 Seconds About 240 days
Four random words 7,776 word list, 4 words 3.7 x 10^15 About 4 days About 11,600 years
Tr0ub4dor&3 94 printable, 11 characters 5.1 x 10^21 About 16,000 years Effectively forever
Six random words 7,776 word list, 6 words 2.2 x 10^23 About 700,000 years Effectively forever
Sixteen random characters 94 printable, 16 characters 3.7 x 10^31 Effectively forever Effectively forever

Two conclusions follow from that table. Length buys far more than a clever substitution does, and a site that hashes with something slow buys you time you cannot manufacture by choosing a better password on a site that hashes with something fast. The original advice to mix case, numbers and symbols still holds, but the arithmetic shows why saying it alone was never enough.

From Passwords to Passphrases

The practical answer for a password a human has to type is a passphrase: several words chosen at random and joined together. Four random words drawn from a list of about 7,700 give roughly the same keyspace as nine random characters from the full printable set, but they are dramatically easier to remember and to type on a phone. Six words take it out of reach of any realistic offline attack even against a fast hash.

Randomness is the part people skip. correcthorsebatterystaple is long, but it is a well known phrase from a well known comic, so it appears in wordlist based rule attacks. Pick words from a generator, or from a physical source such as dice, not from whatever is on your desk. A four or five word phrase chosen by hand is usually far weaker than it looks.

Deliberately mangling one memorable base password per site, for example MyPasswordGitHub and MyPasswordWork, is a common compromise and a poor one. Once one breached site exposes the pattern, every other account that follows it is trivially derived.

Password Managers

The only realistic way to follow the first tip in this post, using a different password for every account, is to stop memorising passwords. A password manager generates a long random value per site, stores it encrypted, and fills it in for you. What you memorise instead is a single strong passphrase that unlocks the vault.

Both major categories work. The manager built into your browser is already there, syncs across your devices and is adequate for most personal use, provided the underlying operating system account is protected and the browser sync is tied to an account with MFA enabled. A dedicated password manager adds organised sharing, audit logs, breach alerts and better handling of one-time codes and passkeys. Whichever you choose, protect the vault with a long passphrase and multi-factor authentication, because it now holds every credential you own.

A practical note on that: the vault becomes a single point of failure, so make sure you have a recovery path, and export a backup before you migrate between managers. If you want to know what is already stored in your browsers and whether it is exposed, Saved Browser Passwords covers exactly that.

Multi-Factor Authentication

Everything above reduces the chance that a password is cracked. Multi-factor authentication reduces the consequence of it being known, and it is the single largest improvement available since this post was first written. If the stolen password alone is not enough to log in, credential stuffing stops working, and the value of a leaked password database drops sharply.

The details matter though. Push notifications that only ask for approval can be defeated by fatigue, where an attacker sends repeated prompts until one is accepted. Number matching and context in the push prompt largely close that gap. Time based one-time codes can be relayed by a convincing phishing page in real time. Hardware security keys and passkeys based on FIDO2 or WebAuthn resist phishing by design, because the credential is bound to the origin and cannot be replayed against a lookalike site.

For organisations the usual path is to add MFA to the systems that already exist rather than replacing them, which is what the Duo proxy and Windows logon components in this blog do: Duo Authentication Proxy Upgrade covers RADIUS and LDAP, and Upgrading Duo Authentication for Windows Logon covers interactive Windows logons. For web applications, identity providers are the other half of the picture, as described in Cloudflare Access IdP with Entra ID.

Checking Whether Your Credentials Have Leaked

You do not have to wait to be notified. Several services will tell you whether a given address or password appears in known breach data, and the password checks are designed so that the password itself is never transmitted in full.

  • Have I Been Pwned searches an address against the accumulated breach corpus and reports which services are affected. It also runs a password check where only the first few characters of the hash leave your browser.
  • Most password managers include a watchtower or breach monitoring feature that audits your whole vault at once and sorts the results by severity. That is more useful than checking addresses one at a time.
  • Browser password checkup utilities flag reused and known-compromised passwords sitting in your browser store.

When you find one, the order of operations matters. Change the password on the affected site first, then on every other site where you used the same value, and enable MFA on the account before you do anything else if it is an email account, because email is the reset path for everything else. Then check for changes you did not make: forwarding rules, recovery addresses, connected applications and payment methods.

Passwords in an Organisation

If you administer accounts rather than just using them, the guidance has shifted since 2012 as well. Current practice, reflected in NIST guidance, is to:

  • Require length rather than composition. A minimum of twelve to fifteen characters for user chosen passwords, and allow much longer.
  • Screen new passwords against lists of known breached and commonly used passwords, and reject matches.
  • Drop arbitrary expiry. Forcing a change every 60 or 90 days produces incremental passwords and a predictable pattern; change a password on evidence of compromise instead.
  • Remove password hints and knowledge based questions, which are weak evidence and often public.
  • Allow pasting into password fields, so password managers and passphrases can actually be used.

Frequently Asked Questions

Are password managers safe?

For nearly everyone they are far better than the alternative of reuse. They concentrate risk into one vault, which is why the master passphrase and MFA on that vault matter so much, but they also let you hold individual, long, random passwords that no human could otherwise remember.

Should I still change my password every 90 days?

No. Arbitrary expiry produces weak variations, costs users time and does not meaningfully reduce risk. Rotate when there is a reason: a breach, a leaked credential, a departing administrator with shared account access.

How long should a password be?

As a working rule, twelve characters of a passphrase or random string is a sensible floor for anything important, and six random words or sixteen random characters puts you beyond practical offline cracking. Note also that two letters gives only 676 combinations and two alphanumeric characters 1,296, both exhausted instantly, because length multiplies the keyspace while a wider character set only multiplies it a little.

Does MFA make a weak password safe?

It removes most of the risk from credential stuffing, and it will not save an account that is being targeted directly. Push fatigue, real time phishing relays and account recovery weaknesses are the remaining paths, and this is exactly why phishing resistant factors such as passkeys and hardware keys matter.

Summary

The original tips in this post still hold: use a different password everywhere, make it long, mix character types and make sure you have a way back in. What has changed since 2012 is the practical way to achieve them, and how much the arithmetic actually matters.

  • Stop memorising passwords. Use a password manager with a long passphrase and MFA on the vault.
  • Reach for length. A six word passphrase beats a nine character mangled word, and it is easier to type.
  • Treat a breach notification about one site as a signal to sweep every account where that password was reused.
  • Add multi-factor authentication wherever it is offered, and prefer phishing resistant factors where the platform supports them.
  • If you run the systems, harden the storage side too: salt your hashes and use a deliberately slow algorithm, because that buys your users time they cannot buy themselves.