How to Choose a Password - Computerphile

  Рет қаралды 1,223,628

Computerphile

Computerphile

Күн бұрын

How do you pick the perfect password? Is it as simple as XKCD make out, or is there more to it? Dr Mike Pound follows on from his password cracking video.
Password Cracking on a 4x Titan X Beast: • Password Cracking - Co...
EXTRA BITS: • EXTRA BITS: Password C...
Indie Game Developer: • Indie Games & the Four...
Indie App Developer: • Life of an Indie App D...
/ computerphile
/ computer_phile
This video was filmed and edited by Sean Riley.
Computer Science at the University of Nottingham: bit.ly/nottscom...
Computerphile is a sister project to Brady Haran's Numberphile. More at www.bradyharan.com

Пікірлер: 2 600
@minihjalte
@minihjalte 8 жыл бұрын
Dr Mike Pound is my favorite presenter on computerphile.
@BattousaiHBr
@BattousaiHBr 8 жыл бұрын
he _pounds_ the information on us.
@andljoy
@andljoy 8 жыл бұрын
He is one of them, Professor Brailsford however is my favorite. Steve furber was also amazing when he was on.
@Malonomy
@Malonomy 8 жыл бұрын
Gotta love Rob Miles too (and Tom Scott of course)
@minihjalte
@minihjalte 8 жыл бұрын
Malonomy Tom Scott isnt really a presenter as he doesnt work at the university
@augustolin15
@augustolin15 8 жыл бұрын
I'm in love with him
@jord99
@jord99 8 жыл бұрын
An excellent poem there at the start: "Some people watching will have good passwords, Some people will have thought about this before, Some people should have thought about this and haven't, And hopefully will, after we talk about this, a little bit more"
@Flexy59
@Flexy59 5 жыл бұрын
69 likes
@Project_Kritical
@Project_Kritical 5 жыл бұрын
jord99 That was amazing.
@Flexy59
@Flexy59 5 жыл бұрын
Truly was. I will paint that onto my wall or tattoo it somewhere
@victoriencornet5714
@victoriencornet5714 4 жыл бұрын
3 years later... I don't know half of you half as well as I should like; and I like less than half of you half as well as you deserve.
@adityapai5147
@adityapai5147 3 жыл бұрын
wah
@Hazzardworks
@Hazzardworks 8 жыл бұрын
"Make a password with words people don't usually use." *changes password to "Nickelbackisagoodband"*
@moloe0
@moloe0 7 жыл бұрын
Hahahahhahaha
@sindreandreandersen5815
@sindreandreandersen5815 7 жыл бұрын
Hazzardworks *logs into your user*
@slickm7
@slickm7 7 жыл бұрын
Appleisnotoverpriced
@cartererickson7395
@cartererickson7395 7 жыл бұрын
Chris McKenzie Nintendoswitchesarenowinstock
@Horny_Fruit_Flies
@Horny_Fruit_Flies 7 жыл бұрын
TrumpIsLikeReallySmart
@chinareds54
@chinareds54 8 жыл бұрын
All this talk about passwords always reminds me of this scene in Harry Potter and the Prisoner of Azkaban (the book at least, not sure if it made it into the movie): In the story, the students have to say a password to get into their dormitory. Because of heightened security, they change the password so often that one of the students with rather poor memory (Neville) ends up writing down the whole list of passwords on a piece of paper. That list ends up getting stolen, defeating the entire purpose of the heightened security.
@tonyhancock1377
@tonyhancock1377 3 жыл бұрын
It would ronelove
@justineberlein5916
@justineberlein5916 Жыл бұрын
No, but that's actually why you *don't* want to force people to change their passwords too frequently. The more frequently you have to change your password, the more likely you are to make insecure ones, to the point that people can sometimes even guess your current password given a list of your previous ones. So frequent password changes actually lead to exactly the sort of security issue that let Sirius break into Gryffindor Tower
@Triantalex
@Triantalex 2 ай бұрын
ok?
@ThePolfAlmighty
@ThePolfAlmighty 8 жыл бұрын
"Computerphile - Making you uncomfortable towards your life choices since 20XX"
@Triantalex
@Triantalex 2 ай бұрын
??
@GGanon
@GGanon 4 жыл бұрын
4 years ago, watching this video made me realize I had a bad password system and I switched to using a password manager. Thanks computerphile
@henilmalaviya
@henilmalaviya Ай бұрын
and here you are after 4 years
@ThalesII
@ThalesII 8 жыл бұрын
It's all fine and dandy until you have to use a website that either: a) forces you to use uppercase, numbers, symbols, runes, smoke signals... or b) limits you password to something like 12-16 characters
@gfrewqpoiu
@gfrewqpoiu 8 жыл бұрын
my Banks Online Banking takes the cake here, they use CONSECUTIVE numbers for the username and exactly 6 Numbers as the password. You CANNOT change the Username and you must use a 6 Number Password
@BoTuLoX
@BoTuLoX 8 жыл бұрын
In my experience banks are the ones with the worst online security of all companies.
@icedragon769
@icedragon769 8 жыл бұрын
That's what password managers are for.
@gasdive
@gasdive 8 жыл бұрын
I'd change banks
@Stars-Mine
@Stars-Mine 8 жыл бұрын
Yea, I would change banks as well. Not only is a 6 charachter set to small, you claim its only a 6 number set. You dont even need one titan to crack that. an 8800 GTX could do it in under a second.
@somedaythewave
@somedaythewave 8 жыл бұрын
now they're gonna use the least likely 10,000 words in the dictionary great going mike
@mensrightsedinburgh4764
@mensrightsedinburgh4764 8 жыл бұрын
Why? most words like that will be words 0.001% of the population even know. things like Nudiustertian.
@somedaythewave
@somedaythewave 8 жыл бұрын
its a joke.
@mika2666
@mika2666 8 жыл бұрын
or just 10.000-20.000 :P
@Kram1032
@Kram1032 8 жыл бұрын
Stackexchange uses a scheme where the 10000 most common passwords are simply disallowed. Otherwise it simply has to be long enough (I think >8 symbols) That seems pretty sensible to me.
@engineerwolf3692
@engineerwolf3692 8 жыл бұрын
never go too common or too uncommon. because they are guaranteed to be on list.
@jumpingspider7105
@jumpingspider7105 8 жыл бұрын
Guys, post your passwords, lets see who's is best!
@raalotephinscorcies5382
@raalotephinscorcies5382 8 жыл бұрын
KZbin automatically conceals passwords in the comment section. See, here's my paypal password: *****************
@Mattimaro
@Mattimaro 8 жыл бұрын
********** Omg, it really does! That is so cool!
@MrZebrot
@MrZebrot 8 жыл бұрын
does it really? password123
@thewolfofthestars1847
@thewolfofthestars1847 8 жыл бұрын
tRoLOloLOloLOl1234
@Rythmbot
@Rythmbot 7 жыл бұрын
bigtittybuttboob14
@tncorgi92
@tncorgi92 8 жыл бұрын
"Pick a word that other people don't use very often, like your favorite band name." lol
@Triantalex
@Triantalex 2 ай бұрын
??
@fruitshuit
@fruitshuit 8 жыл бұрын
I'd be interested to hear Mike talk about workplace password resets. Lots of places I've worked require employees to reset their passwords every month, and some have onerous requirements for length and symbol usage. I think that rather than improving security, it encourages people to make passwords easy to guess (since they expect to forget), or worse, actually write their passwords down and stick them to the computer.
@Triantalex
@Triantalex 2 ай бұрын
false.
@Huntracony
@Huntracony 8 жыл бұрын
I´ve had multiple sites/servises tell me my password is too long, and even had one telling me I couldn´t use special characters. How am I supposed to have a safe password when you don´t let me damnit.
@laharl2k
@laharl2k 8 жыл бұрын
if the account isnt too important make the password jfjfuenx;3*7bckflDam#,3:#ebuxBDUgrjrb&{¥¡cjDNdu47`¥ejbxkif and put it in a txt in a pendrive or somewhere in your documents. if you can go stronger by lenght go stronger by user a more dificult charset
@emanwe01
@emanwe01 8 жыл бұрын
If those sites are doing that part wrong, they've probably got other security holes, too. :/
@bobzone09
@bobzone09 8 жыл бұрын
That would require me to switch banks entirely :/
@icedragon769
@icedragon769 8 жыл бұрын
+Laharl Krichevskoy Did you miss the part where he said "I´ve had multiple sites/servises tell me my password is too long, and even had one telling me I couldn´t use special characters. "? Also, please please please don't put passwords in text files. If you're going to use super-strong random passwords, use a password manager.
@ahmh1000
@ahmh1000 8 жыл бұрын
When it is a one off site that i probably won't visit again i just write heyhey, maybe adding a capital letter or a number if needed.
@elave16
@elave16 8 жыл бұрын
as a person that speaks 4 languages I changed my password to 4 words in 4 languages
@MrBibo2050
@MrBibo2050 4 жыл бұрын
//Rule successfully added to dictionary for user: [elave16]
@Ludvigvanamadeus
@Ludvigvanamadeus 4 жыл бұрын
@@MrBibo2050 yeah, know that you know his scheme it's a piece of cake, you just need to guess which 4 of the thousands of languages out there he used (it might include fictional languages like Eldar, Dorthraki or Klingon), narrows it down to just ~4^(10^7) or so possible passwords..
@pmj_studio4065
@pmj_studio4065 4 жыл бұрын
That's what I thought, use as many languages as you can, but not English or your first language.
@brusch1553
@brusch1553 4 жыл бұрын
@@pmj_studio4065 dont use any languange. I mean just dont use meaningful words
@gabrielhorth
@gabrielhorth 4 жыл бұрын
Yo_savais_你_would
@FrederikHanghjIversen
@FrederikHanghjIversen 8 жыл бұрын
I think this presentation is brilliant. I have one small point to make when it comes to random websites that require you to make an account. If the website is not going to be storing sensitive information, then surely just using a week password to circumvent this annoying requirement of having to create an account is not much of an issue.
@delacreaux
@delacreaux 8 жыл бұрын
To emphasise the point made around 4:17 , just for fun, I tried typing in "correct horse battery staple" into the password strength checker for my Google account. It was considered strong up until I finished typing the last word, at which case it dropped to medium, so he's absolutely right that XKCD's password is not a good choice, just like any other password everyone knows.
@maxuix2
@maxuix2 8 жыл бұрын
2 more of these vids, and we'll socially engineer his master password boys!
@Triantalex
@Triantalex 2 ай бұрын
??
@AndrewMeyer
@AndrewMeyer 8 жыл бұрын
1. 4:59 He addressed that: "(You can add a few more bits to account for the fact that this is only one of a few common formats.)" 2. 5:42 The comic assumed the top 2048 words. You can tell based on the bits of entropy in the illustration. One thing I think would be great to mention here is diceware. A nice system for choosing passwords that makes it easy for you to generate memorable passwords with any level of entropy you desire. I use around 100 bits of entropy for my low security master password, and ~120 bits for my high security master password.
@DJoppiesaus
@DJoppiesaus 8 жыл бұрын
Always when I type a password it gets replaced with * or •, and that's so easy to crack! They really need to fix this!
@tuneboyz5634
@tuneboyz5634 5 жыл бұрын
Thats hiding the password dumbass
@SabyasachiGhosh1618
@SabyasachiGhosh1618 5 жыл бұрын
r/whoosh
@zionj104
@zionj104 5 жыл бұрын
@@tuneboyz5634 THATS THE JOKE
@doubledenial8178
@doubledenial8178 5 жыл бұрын
@@tuneboyz5634 Yeah but they're hiding the password with a single character, that can't be secure
@1_adityasingh
@1_adityasingh 5 жыл бұрын
@@tuneboyz5634 r/woosh
@uuu12343
@uuu12343 7 жыл бұрын
"Maybe delete your account out of shame" *proceeds to face palm* Straight savage
@Triantalex
@Triantalex 2 ай бұрын
false.
@raymondlinz1333
@raymondlinz1333 7 жыл бұрын
Love these videos. Great presentation Dr. Mike! On the subject of choosing passwords, I've ran across something odd myself. A password is something you use over and over again. I've used it as a psychological tool. My password is a positive affirmation of a couple short sentences. If you are going to type it over and over again, then why not? I feel that I perceive a difference in myself just because I changed the password I type constantly. Also cracking full sentence passwords might be hard :)
@brandonthesteele
@brandonthesteele 8 жыл бұрын
My favorite stuff is the "Secret Question" stuff that pops up when I forget my password or when I need to answer a "shield" question. I give wrong, easy to remember answers to the questions about what my first car was, where I went to Elementary school, etc. If I get to make up my own question, then it's REALLY fun.
@TheScrowlingFender7
@TheScrowlingFender7 2 жыл бұрын
I recently started to use my generator for the security questions but I don't get asked them as much by sites as I used to.
@rylog8
@rylog8 3 жыл бұрын
"Oops! Your password is too long!" "Oops! You need to include a number, a symbol, and an upper and lowercase letter" "Oops, that character is not supported!"
@benjiusofficial
@benjiusofficial 3 жыл бұрын
@Manner Josh verb please
@TheScrowlingFender7
@TheScrowlingFender7 2 жыл бұрын
That's the worst. That's why I put those rules in the notes section of that site's entry.
@Triantalex
@Triantalex 2 ай бұрын
??
@Parker8752
@Parker8752 8 жыл бұрын
How about using more than one language in the password? For example, horsecaballocapallceffyl is just horse in English, Spanish, Irish and Welsh - unless the hacker tries dictionary attacking you with multiple languages at once (which would surely increase the search space to the point of absurdity), that should be safe, still only requires you to remember four words, and most people know at least some words from a foreign language.
@kaitlyn__L
@kaitlyn__L 8 жыл бұрын
what about not even making them the same word but in different languages, just slip in a japanese word or a portugese word or whatever, as one of them
@Parker8752
@Parker8752 8 жыл бұрын
My example was only the same word because I was lazy and didn't feel like putting multiple words through google translate ;).
@ukbenji
@ukbenji 8 жыл бұрын
+Parker8752 gotta throw In a _ mid letters and they shouldn't have a chance of getting it :D
@mtvirux
@mtvirux 8 жыл бұрын
passwordunodeuxsthree incoming...
@rikanoniem5214
@rikanoniem5214 8 жыл бұрын
That sounds alright at first glance, until you realize the search space is actually quite low because you still used a common English word as the base component. Say, the dictionary is a top 1000 of English words with european translations. Assuming that horse is in there, your password is going to be in there. I'd say that, to actually benefit from multiple languages, do use a set of different words, in the different languages.
@djmips
@djmips 8 жыл бұрын
Finally! someone who points out the issues with the XKCD system.
@joshua43214
@joshua43214 8 жыл бұрын
He nailed about putting a random underscore in a word. Pass phrases that use random characters inside words are fairly easy to remember and very hard to crack.
@AgentM124
@AgentM124 8 жыл бұрын
it would be something if your 128 character uber password gets a hash collision with the password "password"
@ThymeCypher
@ThymeCypher 8 жыл бұрын
Which is why using MD5 is very much no longer the recommended hashing method.
@fgregerfeaxcwfeffece
@fgregerfeaxcwfeffece 8 жыл бұрын
You know that this is already so much more unlikely then getting struck by a lightning and eaten by rabid squirrels afterwards that this argument is somewhat ridicoulous? In Fact getting attacked by rabid squirrels has happend way more often then successfull attacks based on md5 collisions. Just google it.
@fgregerfeaxcwfeffece
@fgregerfeaxcwfeffece 8 жыл бұрын
any scientific proof of that or just your holy book? edit: apparently the post this was meant to answer was deleted, so we got our answer.
@JellyMyst
@JellyMyst 8 жыл бұрын
Come on now, person who mixed up username and password when making your KZbin account, that's clearly not an argument of any sort. It's a joke.
@FathinLuqmanTantowi
@FathinLuqmanTantowi 8 жыл бұрын
nice password there.
@Meanie010
@Meanie010 8 жыл бұрын
I just use the entire lyrics of bohemian rhapsody as my password. It makes every login attempt a rock concert.
@kathanshah8305
@kathanshah8305 3 жыл бұрын
No time for losers
@cynical5062
@cynical5062 3 жыл бұрын
Me: uses the lyrics of Never Gonna Give You Up as my password, therefore rickrolling anyone who tries to login to my account.
@Triantalex
@Triantalex 2 ай бұрын
ok?
@TheVirIngens
@TheVirIngens 8 жыл бұрын
More tips: - Mix different languages - Use phonetic spelling instead of the dictionary version
@ragnkja
@ragnkja 7 жыл бұрын
And if you use phonetic substitution (a common example in English would be to replace "for" with "4") in the middle of one of your words, use one of those other languages. (The main reason I don't use more words from my north-Norwegian dialect than I do is that a lot of them need letters that require a Norwegian or possibly Danish keyboard to write, which is a problem if I ever need to write them on a different keyboard.)
@starlight4497
@starlight4497 5 жыл бұрын
Another tip is to legit put spaces into your password. Means a brute force attempt will never work, or so I have been told
@thanushehehe7302
@thanushehehe7302 5 жыл бұрын
You can’t mix languages in Some websites
@Scarletraven87
@Scarletraven87 5 жыл бұрын
Use your dialect, if you have any Use your dialect in phonetic, if you can Use your dialect in phonetic and add symbols if you like But in the end, don't use it everywhere, cause a single cracked database screws you over everywhere else.
@dycedargselderbrother5353
@dycedargselderbrother5353 4 жыл бұрын
I've gotten permanently locked out of accounts using non-7bit characters. In a few cases it looked like I damaged their database or something given how the site behaved when trying to login or reset the password. This is gradually less of an issue over time but at least once upon a time a lot of sites appeared to use hand-rolled systems that didn't sanitize input.
@Kek5kopF
@Kek5kopF 8 жыл бұрын
That video was very good, I learned a lot. Another approach for coming up with safe passwords is generating a bunch of random passwords and modify them so you can find some meaning and remember it easier.
@VoxAcies
@VoxAcies 7 жыл бұрын
People argue that using a password manager is putting all eggs in one basket, but you can mitigate that by using multiple databases with different keys. The alternatives are always worse, unless your memory is phenomenal and you can remember 100 different complex passwords. Another way is to have some sort of algorithm to generate passwords for different things (which is essentially your own private hashing method), but it can also fail, if some input data changes (e.g. a website URL, name etc). Password manager is easy to use, reasonably secure and has manageable risks. It's the way to go for most people who care about these things.
@NickMachiels
@NickMachiels 8 жыл бұрын
great effort on spreading password and IT security awareness!
@matthewthomas4620
@matthewthomas4620 8 жыл бұрын
For cases where you cannot use a password manager (ex. the password for the password manager) I have found a sentence mnemonic to be capable of generating easy to remember (even when seldom used) passwords that as far as I know are fairly tough to break. Obviously they need to be long enough, especially considering that the character set is somewhat restricted and certainly biased, but they are much better than what many people use for cases where a manager is just not an option. example: PW = Wyu#THHymc23 Mnemonic = (W)hen (y)ou (u)se Hashtag(#) (T)he (H)oly (H)and-grenade (y)ou (m)ust (c)ount to(2) three(3) The PW is dictionary proof, and while not truly random has high enough entropy that I imagine it is reasonably safe from brute force. Certainly their are weaknesses in such a password. It is not random. However you can easily remember very long passwords that contain mixed case, numbers and symbols without any English words. Thus providing reasonable security when you cannot use a password manager.
@ragnkja
@ragnkja 8 жыл бұрын
If you're multilingual, perhaps use a combination of words from the languages you speak. For instance, to crack a password that's a combination of Norwegian, English and German words (or any subset of the three), you would need to search a pretty big search space in order to find whichever one I might have chosen.
@Jure1234567
@Jure1234567 6 жыл бұрын
How about this method: you pick a simple password you like of any length, then you open online hashing website and make say md5 hex characters string from it with no spaces, lowercase. Then you simply use that md5 as you register on some website. Then when you need to log in, you just do this again - open any online md5 calculator, enter your simple password and get the hash string, then paste it to a password field in a login page. Simple and no password manager needed. If you want make it more secure - use sha256 or some rare online hasher like say shark or something.. You might simply use CRC64 online calculator, however in this case you have to make sure this is a correct type of CRC. You might also use only first say 10 characters of that md5, or md5 without last say 5 characters, or hash twice md5-md5 or combined md5-sha1 or md5-base64 for example.
@sieevansetiawan4792
@sieevansetiawan4792 4 жыл бұрын
I think you should convert/hash it locally.
@Ken.-
@Ken.- Жыл бұрын
I love that people think making a password different is just putting the name of the site on the same password they use everywhere.
@DillonStrichman
@DillonStrichman 8 жыл бұрын
Password cracking groups watching this video, furiously scribbling notes about giving low-frequency words a higher precedence
@danielbengtsson9833
@danielbengtsson9833 6 жыл бұрын
It'd be interesting to hear his opinion on mixing languages. Let's say you have a 3 word password, you seperate them with spcial characters and then the first word is english, the second is japanese for example and the third one swedish. Would that break these rainbow lists of hashes?
@DarioVolaric
@DarioVolaric 8 жыл бұрын
I always make my passwords 'incorrect'. So whenever i forget my password it will say 'your password is incorrect'
@caldrago1470
@caldrago1470 8 жыл бұрын
*slow clap*
@LandoCalrissiano
@LandoCalrissiano 8 жыл бұрын
This fried my slow clap processor.
@PGGerz
@PGGerz 8 жыл бұрын
I make my password "*******" so they think its encrypted
@caldrago1470
@caldrago1470 8 жыл бұрын
it_twit - Redstoner&Mapmaker Now that is a joke I can bear because I haven't seen it chewed up and spat out hundreds of times before.
@threeqtrsnorthrn1669
@threeqtrsnorthrn1669 7 жыл бұрын
My password is : bythetimeyouhaveguessedmyrealylongpasswordiwillhavestileyourbagel
@redanwrong
@redanwrong 8 жыл бұрын
been using one of these managers, dad got me into it, but this video convinced me to change the master
@gabrielmarciu69
@gabrielmarciu69 8 жыл бұрын
I love steam, they don't have any restriction other than the character one. Nice video, changed my password everywhere now :)
@macronencer
@macronencer 8 жыл бұрын
I got a lot more canny about passwords a few years ago, and have adopted a common scheme for them. I thought this would mean I could remember them all much more easily and still be secure. But the really irritating thing is that whatever rules I choose, there always seems to be one web site that will moan about my choice of characters. Some of them even tell me I can't use a password because it is too LONG. WTF? Are they even hashing it?? Have to wonder. It would be nice if there were an RFC or some kind of standard that all sites followed: then we could all use a scheme and be sure that it would be acceptable in most places.
@jamesedwards3923
@jamesedwards3923 5 жыл бұрын
This is why you use password managers of some sort. Dude are trying to account for something others did not care about. Stop it, you know depending on the site password restructions are horrible to none at all. Find some way to secure your passwords and use it. Notice that most places that get hacked do not tell you what hash they used. Which means the hash is not even a 256 bit hash. Which means it is probably SHA-1 or MD5 with low ittrations. Or worse no ittrations.
@franspigel9281
@franspigel9281 3 жыл бұрын
From the video you're commenting on: "password systems in general are not a very useful way to authenticate, because they're hard to remember, unless you pick an easy one to remember, in which case it's easy, and not secure. So in some sense we've tried to find a way of authenticating ourselves which is hard for a human to remember, easy for a computer to guess, and people do it badly. "
@macronencer
@macronencer 3 жыл бұрын
@@franspigel9281 I generally agree, though I do think there *are* ways to make passwords easy(ish) to remember and also hard to crack :)
@phizlip
@phizlip 2 жыл бұрын
@@macronencer passphrases are the future
@Triantalex
@Triantalex 2 ай бұрын
ok?
@picassodilly
@picassodilly 4 жыл бұрын
A great easy to remember/ hard to crack password I’ve heard is take a song lyric or quote, then use only the first letter of each word in it- For example, “unwritten” Staring- At The Blank Page Before You, Open Up The Dirty Window Reaching- For Something In The Distance So Close You Can Almost Taste It Feel The Rain On Your Skin becomes “satbpbyoutdwrfsitdscycatiftroys” Throw in a few symbols at The pauses in the song for extra security and good luck finding that in a dictionary attack. (You’ll probably want to use a more obscure song, just to be safe)
@richkitten9539
@richkitten9539 4 жыл бұрын
But that’s easier to crack if you know that’s what the person is doing. Given a few thousand songs, the number of possible passwords is far more limited than if you randomly arranged some words
@kevinskipp2762
@kevinskipp2762 3 жыл бұрын
@@richkitten9539 I do something similar but use random lines i.e. not consecutive line from one song/poem but separate lines from different songs/poems or quotes, and also mix up which letter I use, so sometimes 1st letter of word, other times last letter, or even both the first and last. Then using symbols in memorable locations.
@desudesu8695
@desudesu8695 3 жыл бұрын
@@richkitten9539 dont tell peopel then xD. "A great easy to remember/ hard to crack password I’ve heard is take a song lyric or quote, then use only the first letter of each word in it-" nobody will ever guess that unless they read this coment thread
@blucat4
@blucat4 8 ай бұрын
@@desudesu8695 Nwegtutrtt
@christiannorf1680
@christiannorf1680 6 ай бұрын
Having to spend a minute trying to sing back a song to yourself in your head while paying attention to which letter each word starts with does NOT count as easy to remember
@fellpower
@fellpower 4 жыл бұрын
"Make a password with words people don't usually use." Changes my password to "brain"
@stumbling
@stumbling 8 жыл бұрын
The cruel irony of this video is the best passwords are the ones no one knows, and the best method for choosing a password is the one no one has told anyone else.
@b.t.burton5000
@b.t.burton5000 4 жыл бұрын
I never thought I would find a Computerphile video from the Avast website
@derstreber2
@derstreber2 8 жыл бұрын
You could pick at least 6 different words, all words being longer than 6 characters each, preferably uncommonly used words, and use words from 2 to 4 different languages (English, French, German, Spanish) while ensuring that words you use don't show up in multiple languages.(If they are going to use a dictionary attack, better give them more dictionaries to look through) Also if you wish, you could misspell one or more of those words in a memorable way. You would need to throw in at least 1 symbol and a capital letter somewhere to make most websites happy but the rest of the password would stand on its own. I would not pick "rubiks" or "lemmings" as both of these things are well known in geek culture. Nor would I choose to use brand names as a list of common brand names could easily be created. My guess is if you ask 100 people to list 20 different brand names off the top of their head there would be quite a bit of overlap. (I think people from a similar locality would have closer matching lists but country wide there would still be a lot of overlap.)
@SuperAWaC
@SuperAWaC 8 жыл бұрын
are you joking? now you've gone off the opposite extreme.
@tsobf242
@tsobf242 8 жыл бұрын
Oh shut up. You can be paranoid all you want, but don't advise others to be too.
@derstreber2
@derstreber2 8 жыл бұрын
+SuperAWaC Not that extreme in my opinion. If you speak multiple languages why not include them in your password?
@derstreber2
@derstreber2 8 жыл бұрын
M. de k. lol yeah like that (although ideally you wouldn't want to share that with thousands of people on the youtube comments) The best part is when people look over at your login and see: ********************************************************************************************* , they think your some kind of super genius demigod.(I have gotten several interesting comments in person. More people look over your shoulder than you would think.) So yeah, there are some benefits of being paranoid.
@diurdi
@diurdi 8 жыл бұрын
Just go straight to Navajo language
8 жыл бұрын
I used XKCD to make an even stronger policy for myself. 4 words of 4 different languages. Example höstjääpalochampionshipmira höst is Swedish for autumn jääpalo is Finnish for the sport bandy mira is Russian for world. my hook to the password is that in the autumn there is a world cup/championship for club teams in bandy. I don't use this particular password, but I think it would be very very hard to crack if I did (and hadn't used it as an example)!
@user-dt4sh9tm2g
@user-dt4sh9tm2g 4 жыл бұрын
it's mir (мир), not mira js
4 жыл бұрын
@@user-dt4sh9tm2g at russian bandy federation, world cup in bandy is Кубок мира .
@JanStrojil
@JanStrojil 8 жыл бұрын
One more point - is there conclusive research on how useful/counterproductive the "change your password every 6 months" policy is? (Especially if the new password can't resemble any of the old ones.)
@RainaRamsay
@RainaRamsay 8 жыл бұрын
I, too, would like to know this. In particular, assuming I do use a password manager, do I have to change my master password every n months? If so, what is n?
@briancarnell
@briancarnell 8 жыл бұрын
Depends on how paranoid you are. The reason you would want to change a password every n months is to make sure if you password is compromised, that the time period in which an attack has access to your accounts is limited. Not sure how realistic that is anymore--most hackers are going to get what they want quickly. I use LastPass and change my master password every year at the beginning of January. This lets me create a strong password that I can commit to memory, while avoiding some of the issues that come about if you never change passwords (like temptation to reuse passwords, etc).
@tncorgi92
@tncorgi92 8 жыл бұрын
When the financial firm where I worked started this policy, we found that most of the users started writing their password on their desk blotters, bottom of their keyboards, etc because they could never remember it themselves.
@Correctrix
@Correctrix 8 жыл бұрын
I wish there were. I certainly know that all it does is force me to use simpler passwords.
@stoppi89
@stoppi89 8 жыл бұрын
Paul Drake Main reason why forcing regular Password changes decrease Security. Forcing the regular change is probably bad 99% of the time if sample size of people is bigger than 6 (means: If you have a group of +6 people and force them to regularly change their password, you gonna have a bad day [sooner or later]).
@zephh_sk
@zephh_sk 6 жыл бұрын
So here's how I figured out my password. On old Nokias 3310 there were games like Snake and Space Impact. I used to play alot of Space Impact and tried to challenge my highscore quite lot of times. Once I've scored a highscore I never ever beaten again. In highscore options you had a code for your highscore (can't quite remember why though) and that highscore was combination of 8 character long random letters and numbers. Since this highscore was so important to me you're damn sure I've remembered that highscore's code and it's my password.
@alialiyev6168
@alialiyev6168 4 жыл бұрын
"You moving your phone out of your pocket, and Google saying you moved your phone weirdly" I have been laughing to this for 5 minutes.
@DanPantry
@DanPantry 8 жыл бұрын
Worth mentioning that it's very unlikely someone will actually get their password database (through keepass or whatever) compromised unless Dropbox (or similar) drops the ball, or an attacker is on your PC. If an attacker is on your PC they can do a lot of things instead of nicking a keepass file and hoping you have something valuable
@justarandompally
@justarandompally 8 жыл бұрын
What about foreign words? Would people run dictionaries for all ~94 generally used languages?
@fdagpigj
@fdagpigj 8 жыл бұрын
And what about extinct/dormant languages like, for example, some of the Sami languages or Livonian?
@ElectricityTaster
@ElectricityTaster 8 жыл бұрын
Robin Williams Just a quick view at your Google+ page and I would say those three languages are English, Spanish and maybe Genoese/Italian.
@robinw77
@robinw77 8 жыл бұрын
agun17 Nice try! :-) One out of three ain't bad, as Meatloaf didn't say ;-)
@ElectricityTaster
@ElectricityTaster 8 жыл бұрын
Robin Williams I'd add german just because it's so popular on the internet and pop culture.
@robinw77
@robinw77 8 жыл бұрын
+agun17 Actually I've been asked if I'm German an unusual amount of times over the years
@astropgn
@astropgn 8 жыл бұрын
yeey! I use a manager for a quite some time now. All my passwords are also 25 random characters (with some superior Ansi characters, like Ų#ҹ) and I don't know what they are :D! One day my friend asked me to log into my FB acc on his computer. I just said I couldn't. And I wasn't lying to him!
@SUFHolbek
@SUFHolbek 8 жыл бұрын
Definitely in my top 10 funniest stories of 2016
@Clownin
@Clownin 8 жыл бұрын
Keep the program and file on an encrypted flash drive. It's what I do when I need to login to something. Also, I have two different files. One for stuff I rarely login to and one that I carry because I know I'll need it day to day. Which password manager do you use?
@emileriksson7689
@emileriksson7689 8 жыл бұрын
what manager is that?
@Clownin
@Clownin 8 жыл бұрын
I use Keepass
@SuperWolfkin
@SuperWolfkin 8 жыл бұрын
if you're using KeePass (like i am) you should keep a copy of your DB on your flash drive. If you trust it keep a copy on DropBox and then connect to it via the KeePass Android App and you can have access to your password via phone.
@arsemonkey2968
@arsemonkey2968 8 жыл бұрын
Choose two random words, convert their letters to numbers using a=1 b=2 c=3 etc... add them together then convert it back into letters. PIG+CAT would end up being 4817 or dhq or dhag. Semi-random letters that wouldn't be hard to remember, and of course you'd choose words that mean something to you and maybe you could throw the numbers back into it, so you could have dhq4817 or 4d81hq7 to make smaller words a little more secure.
@jiffylou98
@jiffylou98 3 жыл бұрын
I probably shouldn't be saying this, but I want a bunch of computerphiles to dissect my system but here goes: I use a sentence in a book I like that has numbers or words that look like numbers. Take the first letter of each word, capitalize nouns, and replace numerical words. The passwords tend to be long because the sentences are distinct. Let me know if I'm a buffoon or a genius
@hellterminator
@hellterminator 8 жыл бұрын
_Never_ reuse a password? I use the same username/password combo for… well, probably hundreds of sites by now, but only for sites I don't care about. It's actually been leaked already, but idgaf. What you gonna do? Steal my account with 0 posts on a random forum that required registration to display URLs I stumbled upon while Googling something a couple years ago? Knock yourself out! I consider those accounts stolen and I'm completely fine with that. Now emails, online banking, social media… that's a different story.
@logicalfundy
@logicalfundy 8 жыл бұрын
Keep in mind that impersonating you is a thing. I've had to scramble to inform friends and family their shared passwords were a problem because I received links to viruses from accounts they had, but had forgotten.
@hellterminator
@hellterminator 8 жыл бұрын
logicalfundy Impersonating me? The whole point is that I'm nobody on these accounts. No contacts, no posts, no personal information (I even use a separate email account for these registrations to avoid spam on my real account). Impersonate me all you want, but there's nothing in it for you.
@fdagpigj
@fdagpigj 8 жыл бұрын
And a separate username?
@Guaulden
@Guaulden 8 жыл бұрын
Actually you could just use 10minutemail, then you wouldn't need to have a separete mail for things like that.
@hellterminator
@hellterminator 8 жыл бұрын
Guaulden I do like 10minutemail, but a separate email is actually easier and more reliable. 1. If the site is slow and the registration email takes longer than 10 minutes to arrive you don't have to remember to extend it every 10 minutes (and be forced to star over if you forget). 2. Many sites block 10minutemail and other similar services. 3. Maybe one day you will actually need to receive an email from one of those sites again.
@ToastiLP
@ToastiLP 8 жыл бұрын
I'll just hope nobody cares enough about me to even try.
@chainingsolid
@chainingsolid 8 жыл бұрын
The cost to try is so low, they don't need to care about you, or even know you exist, it automated!
@rmsgrey
@rmsgrey 8 жыл бұрын
Security through obscurity isn't terrible, but it's also not reliable. Sure, hacking into Bill Gates' online banking service would be great, but if you can set up a distributed attack that gets online banking details for a thousand people, you can probably get more money before anyone catches on that something's wrong, and you can pick off the thousand people with the weakest passwords rather than having to crack strong ones. Also, posting something like that on a video about password strength is like daring someone to crack your password - it massively reduces the obscurity you're relying on for your security...
@guraski
@guraski 8 жыл бұрын
that should be your password
@dave5194
@dave5194 8 жыл бұрын
+Sam Lenz but now everybody knows it 😯
@psychic8872
@psychic8872 8 жыл бұрын
You are right but the limits mentioned in the video I think are in case someone has access to the hard drive. Besides most sites and especially banks block login attempts after a few tries.
@xxertad
@xxertad 8 жыл бұрын
I had to change all my passwords after watching this
@TheEightfoldPath_
@TheEightfoldPath_ 7 жыл бұрын
If the 4 word method (or something like it) becomes common it would be wise to ignore sentence structuring as that would easily be implemented in a dictionary. I guess even the ordering of subsequent adjectives would matter. Better with greenharrowingbigflute than harrowingbiggreenflute.
@TjPhysicist
@TjPhysicist Жыл бұрын
6:18 a great way to pick "hard words" is for polyglots by using transliterations from words in other languages. Even better if the language doesn't use the latin or related alphabet system. For e.g. i can say "correctkudhiraibatterystaple" "kudhirai" is possible transliteration of the tamil word for horse, more to the point because tamil uses phonetic writing system there's a few ways you can write that in latin alphabet, in fact googling the word gives me the spelling of "kutirai". This would be nearly impossible to dictionary attack in some cases at least. This then comes down to social attack vectors, "does the person who is guessing your password know that it's yours and know about you enough", but even that's easily defeatable, he hinted at this a bit but you can make up words, or use words in languages you don't use often (e.g. being canadian i know a few french words but not french itself so sticking a random french word in there would be completely unexpected).
@Ken.-
@Ken.- Жыл бұрын
Mathematically it would be stronger to just add one more English word than worrying about multiple languages.
@JohnDoe_1237
@JohnDoe_1237 8 жыл бұрын
learn german and use only ONE word :D some LONG german words: Grundstücksverkehrsgenehmigungszuständigkeitsübertragungsverordnung or maybe Verkehrswegeplanungsbeschleunigungsgesetz, or Unternehmenssteuerfortentwicklungsgesetz. you also could combine this three words xD
@JohnMichaelson
@JohnMichaelson 8 жыл бұрын
It'd be more secure to reverse one of them.
@dave5194
@dave5194 8 жыл бұрын
+John Michaelson but would be incredibly hard to remember
@psychic8872
@psychic8872 8 жыл бұрын
That could be cracked by using a dictionary of the 1000 longest german words (or 1000 long common words in general). Reversing or other tricks will not increase entropy much and will make it even harder for you to remember or make a mistake in typing.
@Encypruon
@Encypruon 8 жыл бұрын
How about welsh? upload.wikimedia.org/wikipedia/commons/e/e8/Llanfairpwllgwyngyllgogerychwyrndrobwllllantysiliogogogoch_station_sign_(cropped_version_1).jpg
@JohnDoe_1237
@JohnDoe_1237 8 жыл бұрын
lol, not bad. we should mix them up ;D
@sallerc
@sallerc 8 жыл бұрын
Also, use 2-step verification on important accounts like your email.
@ToveriJuri
@ToveriJuri 8 жыл бұрын
But don't be a popular public figure with a shitty phone company. In that case use cheap GSM phone with a prepaid SIM card that's not linked to your name in any way.
@ryanprov
@ryanprov 5 жыл бұрын
The problem is not to 2FA, the problem is that SMS is not a secure 2FA. It is really easy for attackers to social engineer employees at cell companies into essentially allowing them to clone your SIM card so that they receive all your texts. Now your 2FA is compromised. And this is not just an issue for public figures... if you work somewhere that handles sensitive information you can be targeted for this kind of attack in order to get your work credentials. I've seen it a surprising amount for people working in tech. Always use a proper authenticator app for 2FA, never use SMS! Some sites (like Google) allow using SMS as a backup for 2FA -- this is a bad idea! Make sure to always disable SMS 2FA or SMS account recovery, it is not at all secure and often is easier than actually cracking your password if the payoff is right (which could be a consequence of your employer, even if you personally don't have a lot of money or anything).
@Triantalex
@Triantalex 2 ай бұрын
??
@Gamesaucer
@Gamesaucer 8 жыл бұрын
The real problem is that many sites REQUIRE you to use several symbols, capital letters and numbers. It's annoying, because it means all my passwords are hard to remember. Sure, I can sprinkle one or maybe two special characters in there but more than that and it becomes even harder to remember.
@MaxMakerChannel
@MaxMakerChannel 8 жыл бұрын
Special characters are difficult to type on foreign keyboards.
@Motorman2112
@Motorman2112 8 жыл бұрын
Doesn't this just make it quicker to brute force too? The attackers knows that they can skip over anything that doesn't meet the published requirements. Yes, the inclusions of symbols make the search space larger, but the exclusion of passwords NOT containing them make it smaller again...
@Gamesaucer
@Gamesaucer 8 жыл бұрын
No they're not. What special characters you can type varies per keyboard type, but there's always a few, like @, ', _, %, §, etc.
@Gamesaucer
@Gamesaucer 8 жыл бұрын
M. de k. Let's not, because it can now publicly be found on the internet.
@logicalfundy
@logicalfundy 8 жыл бұрын
. . . which is why you should do what he explained at the end of the video: Use a password manager.
@ignas.c
@ignas.c 2 жыл бұрын
I swapped to password manager the same day after watching this video, to be honest. :D Anyway, another cool idea, following the rules discussed in this video: if english is your second language - mix the words in english and your mother tongue. Now hackers would have to use two times bigger dictionary (english and your mother tongue), stick a random symbol in one of the words and hackers can kiss your password goodbye until quantum computer era comes.
@oops8685
@oops8685 7 жыл бұрын
Password Manager + 2FA = best security I can think of. Even they get your master password, they can't do much unless they also have your 2FA device. I personally use LastPass with sesame, and google authenticator as a backup. On top of that I also have 2FA for alot of my specific accounts such as my google account, facebook, amazon, etc. so even if they SOMEHOW get through my LastPass and have all of my other accounts, they still need my phone to get into those accounts.
@Squidward1314
@Squidward1314 8 жыл бұрын
Yesterday I had to create a new password on a library website. It forced me to pick one with the length 6 or less. I mean really?
@catfish552
@catfish552 8 жыл бұрын
Password manager: Literally putting all your eggs in one basket.
@redsunrises8571
@redsunrises8571 8 жыл бұрын
but its one very strong basket
@AndrewMeyer
@AndrewMeyer 8 жыл бұрын
Password manager: Putting all your eggs in one safe Password reuse: putting all your eggs in one safe and giving a key to the safe to everyone in your neighborhood Weak passwords: putting your eggs in a wicker basket that could fall apart at any minute
@catfish552
@catfish552 8 жыл бұрын
Literally literally.
@EvolBob1
@EvolBob1 8 жыл бұрын
+catfish552 - This is a virtual world - literally. :)
@clementella
@clementella 7 жыл бұрын
I perfer to put my passwords in no baskets just let them float around in my hard rive and interne tI don't care.
@GentlemanlyOtter
@GentlemanlyOtter 5 жыл бұрын
“ *Stylistically* speaking, Java is my favourite programming language.” CSS: Am i a joke to you?
@lkajsdflkasjdf1597
@lkajsdflkasjdf1597 6 жыл бұрын
I do know that most people favor food is pizza or hamburger. When I worked for sprint people called in all the time wanting to reset their password for their google account. That is always the answer to that security question. I worded with them for 2 years and never seen that one fail. Also, here is what I use for a password. I take my name (first if it is a password word for fun and last if it is a password for business) then I go first letter then last letter then second letter then second to last letter and so on. Then add numbers at the end for how important it is from 1 to 100. I do wish you luck to anyone wanting to crack that one. Oh and random letter generaters that you make yourself Java makes this easy. I used Csy5LkbrAQn3 for a long time. It was my MMO password when I played MMO's
@drax9609
@drax9609 8 жыл бұрын
After watching this I immediately went to lastpass and created an account. Thank you very much
@TheWanderer1000000
@TheWanderer1000000 6 жыл бұрын
My password is pretty damn clever. Sadly I can never share it with anyone. *FeelsBadMan*
@kellynolen498
@kellynolen498 4 жыл бұрын
Thats only 3 words super crackable all in the top 300 words and just because you used damn doesnt make it better
@norb3695
@norb3695 2 жыл бұрын
@@kellynolen498 That's not their password xD I know i'm late
@Triantalex
@Triantalex 2 ай бұрын
ok?
@TheWanderer1000000
@TheWanderer1000000 2 ай бұрын
@@norb3695 Yes. I meant my password has all things you need. Upper and lowercase letters, numbers, symbols, and spaces. Thank you for not being surface level. Like everyone else on this site.
@Yemto
@Yemto 8 жыл бұрын
How about using words in another language, or every word in a different language?
@lewismassie
@lewismassie 8 жыл бұрын
That is an interesting point. How long would it take to find a password written in four different obscure languages
@Anonymous-jo2no
@Anonymous-jo2no 8 жыл бұрын
I was about to say it... I know some long words from two foreign languages (not including my native tongue, English, and the language I studied until B2).
@ragnkja
@ragnkja 8 жыл бұрын
If you speak multiple languages, combine them!
@スパイシーな男の子
@スパイシーな男の子 8 жыл бұрын
Unless you know the languages well, then this kind of password just becomes difficult to remember and not really any more secure.
@brandonmtb3767
@brandonmtb3767 6 жыл бұрын
The fact you mentioned this makes it a tactical that someone could use to crack it. Passwords must be as long as possible and random lEtTeRs and $ymb0|s
@Onychoprion27
@Onychoprion27 8 жыл бұрын
You can also use conlangs, if you're nerdy enough. Nobody expects the Klingon Inquisition.
@lylaley
@lylaley 8 жыл бұрын
I use a complex pw like D1%jdpVq/2pf_6 (not mine ;)) I memorized it and the trick is that 3 letters are abstracted from the website or password use, so every pw is different by 3 letters. I just need to know the standard and fill the 3 gaps with the specific ones. Example: use for letter 5 the 3rd letter from the domain name and for letter 7 the 1st. You get the idea. Cons: - You have to take care one doesn't guess your system (how you get the extra letters) - difficult to type on touchscreens (though I'm quite fast) Pros: - No pw manager needed - Quite save - Sometimes you are not allowed to use some special characters etc. And for pw which are not important (onetime use, forum, untrusted sites, ...) I use a more simple one at several services which I don't mind getting hacked. So I minimize the chances someone gets knowledge of my pw system. What do you think?
@Battusai1984
@Battusai1984 8 жыл бұрын
As a small side project while i was learning c# i made something in wpf that does the same thing as a password manager, I use three root words and the sites name press enter and it produces a garbled mess of a string i then use as a password, i then paste that in the form/loginbox, besides just having been a fun thing to get working (Z+4=space) i don't have any worries about server or local, or keyloggers since i don't actually ever type the password. If you want to make the "four random words" even more secure, type two of them backwards.
@LudwigvanBeethoven2
@LudwigvanBeethoven2 6 жыл бұрын
"Never ever reuse your password, ever" Me: I Always everytime reuse my password, everytime.
@thanushehehe7302
@thanushehehe7302 5 жыл бұрын
♫♪Ludwig van Beethoven♪♫ Never ever Reise your password ever is my password
@robertgregory2618
@robertgregory2618 5 жыл бұрын
He means at other sites.
@Triantalex
@Triantalex 2 ай бұрын
ok?
@General12th
@General12th 8 жыл бұрын
"unbruteforceable" Brilliant word. Should be in every dictionary.
@roflchopter11
@roflchopter11 4 жыл бұрын
It's probably in his password
@pbpbpbpbpbpbpbpbpb
@pbpbpbpbpbpbpbpbpb 8 жыл бұрын
Pick some book. Write down a sentence. Insert some underscores and miss some spaces. Done.
@Triantalex
@Triantalex 2 ай бұрын
??
@jamesedwards3923
@jamesedwards3923 6 жыл бұрын
The biggest problem with password restrictions. Is that many websites and services are fairly lazy. If you set the limit to one trillion characters. With a full character sets. I assure you. You can have secure passwords because most people can not remember trillions of 'random' characters. However, if you use a series of phrases. Not only can your password be long and complicated. It would also be strong enough to remember. Strong enough to resist brute force and dictionary attacks. Passwords are hard for me to do at work because I am restricted to what the passwords can be. Same thing when using some websites or services.
@inthefade
@inthefade 8 жыл бұрын
I often use my passwords on accounts at friends' houses or on their phones. Usually if I don't have my phone on me, or like recently when I broke it. This makes a password manager completely impractical.
@streamingmadman2427
@streamingmadman2427 7 жыл бұрын
Can you recommend a great password manager?
@EvoX180
@EvoX180 6 жыл бұрын
Streamingmadman lastpass
@jamesedwards3923
@jamesedwards3923 5 жыл бұрын
KeePass or Password Safe.
@Verrisin
@Verrisin 8 жыл бұрын
except most sites will force you to have 6--12 char long password with symbols and numbers in it - you know... so it's safe....
@ChristopherPuzey
@ChristopherPuzey 8 жыл бұрын
Is c0/\/\pu73rp4i|e ok to use for youtube?
@LlamaFluff
@LlamaFluff 8 жыл бұрын
Yes
@kanjitard
@kanjitard 8 жыл бұрын
Not anymore
@mothman.industries
@mothman.industries 8 жыл бұрын
Damnit, how'd you know?
@miroslavhoudek7085
@miroslavhoudek7085 8 жыл бұрын
That wouldn't work for me, it's my mom's maiden name :-/
@25NN25
@25NN25 8 жыл бұрын
awww see what u did there :3
@Twisted_Code
@Twisted_Code 5 жыл бұрын
Ha, that XKCD comic is EXACTLY what I was thinking of when I clicked on the link to this video. Once upon a time, I think I even used "correct horse battery staple" as part (not the whole thing. I'm not that crazy) of a password. I'll be darned if I can actually remember where I used it. Welp, guess I'll be resetting that one if it's not stored in my password manager!
@davidcharles3230
@davidcharles3230 8 жыл бұрын
Great video! Would love one on the implications that will arise with the advent of quantum computing, particularly with respect to current encryption models and what will be needed in the future.
@PhilHibbs
@PhilHibbs 8 жыл бұрын
You should have mentioned the XKCD about the 5$ wrench.
@davidtiganila27
@davidtiganila27 8 жыл бұрын
the solution to that is to string together four physical locks - physical locks can easily be broken, but if you have enough of them, the attacker will get bored and go home : D
@markallen7294
@markallen7294 6 жыл бұрын
Phil Hibbs i
@roflchopter11
@roflchopter11 4 жыл бұрын
@@davidtiganila27 the wrench is used on the person suspected of knowing the password (or their loved ones)
@Triantalex
@Triantalex 2 ай бұрын
false.
@Androidonator
@Androidonator 7 жыл бұрын
what if my database is sheet of paper can they hack it ?
@lilyliao9521
@lilyliao9521 7 жыл бұрын
Matouš Hrdlička yes
@jamesedwards3923
@jamesedwards3923 5 жыл бұрын
A physical paper. Where you did not make the password cryptic is insanely foolish. You do not write down the password. You give yourself hints. Like in password recovery options and the like. Some people do do that. Writing down your actual passwords is something you should 'never' do for the long term. Store your passwords in some sort of encrypted file system.
@danielchin1259
@danielchin1259 4 жыл бұрын
Encrypt it
@Clout253
@Clout253 4 жыл бұрын
He’s
@Triantalex
@Triantalex 2 ай бұрын
??
@captainsparklezx13
@captainsparklezx13 7 жыл бұрын
I have 4 main passwords. Level 1 (sites i dont care about/my spam email, 1 uppercase and 1 lowercase):********** Level 2 (my pc password and my secondary email password, contains lowercase and 1 special character):************ Level 3 (my steam password, my main email password and social media password, contains upper lower numbers and special characters):************** Level 4 (my bank account password only, contains upper and lowercase with special characters):********************** I dont mind my 3rd level password being linked to those 3 accounts since I cycle it every year. Also Howsecureismypassword.net says my level 4 would take about 42 sextilion years to crack it.
@andreasegger4277
@andreasegger4277 5 жыл бұрын
Howsecureismypassword.net also says that you'd need 4 years to crack "password1234". So I wouldn't trust them that much.
@karlmuster263
@karlmuster263 8 жыл бұрын
I took a class that gave us randomized passwords, and I just memorized that because the process of creating your own was confusing. It's pretty great, especially sites that require caps, symbols and numbers.
@cmwh1te
@cmwh1te 8 жыл бұрын
You just announced online that you use this one password for all your accounts. Go change them now.
@karlmuster263
@karlmuster263 8 жыл бұрын
But I don't. All I really announced was that my password for sites requiring those things can only be brute forced.
@VooDooTube...
@VooDooTube... 3 жыл бұрын
CREATING A PASSWORD -Please enter your new password. “cabbage” -Sorry, the password must have more than 8 characters. “boiled cabbage” -Sorry, the password must contain 1 numerical character. “1 boiled cabbage” -Sorry, the password cannot have blank spaces. “50stupidboiledcabbages” -Sorry, the password cannot use more than one upper case character consecutively. -50StupidBoiledCabbagesShovedUpYourArse, IfYouDon’tGiveMeAccessImmediately” -Sorry, the password cannot contain punctuation. “NowIAmGettingReallyPissedOff50StupidBoiled CabbagesShovedUpYourArseIfYouDontGiveMe AccessImmediately” -Sorry, that password is already in use.
@freibuis
@freibuis 8 жыл бұрын
problem with some place where they only allow a small password length :( sad panda
@BattousaiHBr
@BattousaiHBr 8 жыл бұрын
you mean _that_ sad panda?
@Rathner
@Rathner 8 жыл бұрын
If they only allow a small password then assume that they have bad overall security and that there is a higher chance that a password leak might happen.
@BattousaiHBr
@BattousaiHBr 8 жыл бұрын
Topstormking this is actually the first time i heard they only allowing small passwords. EDIT: just tested with a 16 length password with special characters etc and it worked fine.
@dospy1
@dospy1 8 жыл бұрын
use only the first N letters of the random password where N is the maximum allowed letters in a password
@andisaidheyyeyaaeyaaaeyaey8612
@andisaidheyyeyaaeyaaaeyaey8612 8 жыл бұрын
The funniest thing was when I constantly had to remake a password for a site because I couldn't log in with it, and discovered that the site only saved say 10 characters. When I tried to log in with my 12 character password it wouldn't take it unless I removed the last two. No warning "your password is too long" when you created it or anything whatsoever. It just didn't save it, and didn't stop you if you tried to log in with a password that was too long.
@aespejolc
@aespejolc 8 жыл бұрын
Deliberate misspelled words could help
@FatheredPuma81
@FatheredPuma81 6 жыл бұрын
My bank limits the length of ones password to I think 8 characters and force you to use a "special character" which they limit you to like . , ? and ! for choices. So my imgur password can be much stronger than my bank password essentially.
@logosimian
@logosimian 3 жыл бұрын
Many such cases. I created a password generator that hashes a long, beautiful sequence of unrelated unicode characters from whater two keys I punch in. There were letters. There were numbers. There were musical notes. Works for most websites. Not for banks. Or Google websites.
@Triantalex
@Triantalex 2 ай бұрын
ok?
@FatheredPuma81
@FatheredPuma81 2 ай бұрын
@@Triantalex Why are you here?
@Brainreaver79
@Brainreaver79 5 жыл бұрын
ages ago, someone told me to take an easy to remember sentence with around 10-14 words, take the first letter of every word the punctuation and fill in 1-3 numbers and those passwords have kept me quiet safe for around 25 years now. the hard part to remember is where you put the numbers. but it still has lower and uppercase,.. numbers and symbols.. with a decent lenght
@Gortart
@Gortart 8 жыл бұрын
You can also use different keyboard layouts. For example "rkdnl" doesn't look like a word but in standard Korean keyboard layout, it spells "가위" which means scissors. I can use this and some random English word to make something like "rksuitdnltea" and it is very hard to crack, but easy to remember.
@marketingdan5007
@marketingdan5007 8 жыл бұрын
I use last pass, gonna make the master pass stronger now though
@cmwh1te
@cmwh1te 8 жыл бұрын
Mine is upwards of 35 characters, and that's still theoretically vulnerable to a motivated attacker.
@r.bresenitz6640
@r.bresenitz6640 5 жыл бұрын
Also: mix languages and include typos.
@CaroFDoom
@CaroFDoom 8 жыл бұрын
How about making an emoji password? That would be the weirdest thing to crack.
@CaroFDoom
@CaroFDoom 8 жыл бұрын
GamerGate Edin True. I might try it in Google though.
@dhkatz_
@dhkatz_ 8 жыл бұрын
You can't use those characters in passwords
@CaroFDoom
@CaroFDoom 8 жыл бұрын
Doctor Jew Very disappointing.
@ErikHuizinga
@ErikHuizinga 8 жыл бұрын
This would work on mobile phones that have emoji readily typeable from the keyboard. However, the website/software must accept strange characters, which often isn't the case. Great idea, though! Better use a strange character using an ALT+[four numbers] code. An alternative is changing to a different keyboard layout (e.g. Dvorak), but still typing on your regular (e.g. QWERTY) layout. This last trick is not practical, though, and easily programmable to convert any dictionary from QWERTY to Dvorak.
@SpudMackenzie
@SpudMackenzie 8 жыл бұрын
We should get Tom Scott to make an Emoji only password manager.
@ToveriJuri
@ToveriJuri 8 жыл бұрын
What about developing as system where you use lengthy but easy to remember sentences. Then you take for example the first 2 or 3 letters from every word and combine them which turn into nonsense, then you "leetspeak" some of them for variation using a system that you remember. Now since the letter combination is already a seemingly random collection of letters the numbers are also seem somewhat random. Then just add some special characters all over the password using a system that allows you to calculate the placements and the special characters from the password itself. I'm not convinced by correct-hor_se-battery-staple and what I described above is actually easy to remember if you use rules that make sense to yourself.
@fabianmartin88
@fabianmartin88 5 жыл бұрын
When you get hash file from server which is using some common library to compute hash, you do not need to hack passwords. All what your program needs to do is to find input which generates the hash which is probably same also on the other server which use same hash lib.
Diceware & Passwords - Computerphile
10:56
Computerphile
Рет қаралды 307 М.
Have You Been Pwned? - Computerphile
10:59
Computerphile
Рет қаралды 481 М.
Support each other🤝
00:31
ISSEI / いっせい
Рет қаралды 81 МЛН
Mom Hack for Cooking Solo with a Little One! 🍳👶
00:15
5-Minute Crafts HOUSE
Рет қаралды 23 МЛН
Man in the Middle Attacks & Superfish - Computerphile
13:29
Computerphile
Рет қаралды 1 МЛН
Running a Buffer Overflow Attack - Computerphile
17:30
Computerphile
Рет қаралды 2 МЛН
Cookie Stealing - Computerphile
16:12
Computerphile
Рет қаралды 1,1 МЛН
Password Storage Tier List: encryption, hashing, salting, bcrypt, and beyond
10:16
LogJam Attack - Computerphile
18:47
Computerphile
Рет қаралды 184 М.
Passwordless Passkey Logins 2023 - Are they Safe for Privacy?
22:27
Rob Braxman Tech
Рет қаралды 26 М.
This is How Easy It Is to Lie With Statistics
18:55
Zach Star
Рет қаралды 6 МЛН
Why π^π^π^π could be an integer (for all we know!).
15:21
Stand-up Maths
Рет қаралды 3,6 МЛН
3 Levels of WiFi Hacking
22:12
NetworkChuck
Рет қаралды 2,5 МЛН
Support each other🤝
00:31
ISSEI / いっせい
Рет қаралды 81 МЛН