Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Thursday, January 01, 2026

Upping the password ante

 kw: computer security, passwords, analysis

Almost thirteen years ago I wrote about making "million-year passwords", based on the fastest brute-force cracking hardware of the time, that was approaching speeds of 100 billion hashes per second. The current speed record I can find is only 3-4 times that fast, at just over 1/3 of a trillion hashes per second, but it is a lot cheaper. It seems the hardware scene hasn't changed as much as I might have thought.

I surmise that more sophisticated phishing and other social engineering schemes have proven more effective than brute-force pwd file crunching. However, the racks of NVidia GPU's being built to run AI training are ramping up the power of available hardware, so I decided to make a fresh analysis with two goals in mind: firstly, based on a trillion-hash-per-second (THPS) potential rate, what is needed for a million-year threshold?, and secondly, is it possible to be "quantum ready", to push the threshold into the trillion-year range?

I plan to renew my list of personal-standard passwords. The current list is five years old, and contains roughly twenty items for various uses. I have more than 230 online accounts of many types, so I re-use each password 10-15 times, and I activate two-factor authentication wherever it is offered. The current "stable" of passwords range from 12 to 15 characters long. I analyzed them based on an "All-ASCII" criterion, but since then I've realized that there are between six and 24 special characters that aren't allowed in passwords, depending on the standards of various websites.

The following analysis evaluates six character sets:

  1. Num, digits 0-9 only. The most boneheaded kind of password; one must use 20 digits to have a password that can survive more than a year of brute-force attack.
  2. Alpha1, single-case letters only (26 letters).
  3. Alpha2, both upper-and lower-case letters (52)
  4. AlphaNum, the typical Alphanumeric set of 62 characters.
  5. AN71, AlphaNum plus these nine: ! @ # $ * % ^ & +
  6. AN89, AlphaNum plus these 27: ! @ # $ % ^ & * ( ) _ - + { } [ ] | \ : ; " ' , . ? ~

The only sets that make sense are AlphaNum and AN71. The shorter sets aren't usually allowed because most websites require at least one digit, and usually, a special character also. AN89 provides a few extra characters if you like, but almost nobody allows a password to contain a period, comma, or any of the braces, brackets and parentheses. I typically stick to AN71.

The calculation is straightforward: take the size of the character set to the power of the password length. Thus, AlphaNum (62 in the set) to the 10th power (for a 10-character password) yields 8.39E+17. The "E" means ten-to-the-power-of, so 1E+06 is one million., a one followed by six zeroes. Negative exponents (the +17 above is an exponent) mean the first digit is that many characters to the right of the decimal point.

Next, divide the result by one trillion to get seconds; in scientific notation, just subtract twelve from the exponent, which yields 8.39E+05, or 839,000 seconds. The number of seconds in one year is 86,400 × 365.2425 (86,400 seconds per day, 365.2425 days per Gregorian year). Divide by this; in this case, the result is 0.0266, or about 9.7 hours.

Are you using a 10-character alphanumeric password? It will "last" no more than 9.7 hours against a brute-force attack with a THPS machine. If you were to replace just one character with a punctuation mark, such as %, the machine would find out, after 9.7 hours, that your password is not alphanumeric with a length of ten. It would have to go to the next step in its protocol and keep going. If its protocol is to run all 10-character passwords in AN71 (perhaps excepting totally alphanumeric ones, since they've all been checked), 71 to the tenth power is 3.26E+18. The number of seconds taken to crack it is now 3.26 million, about a tenth of a year: 38 days.

We're still kind of a long way from a million-year level of resistance. To save words, I'll present the full analysis I did in this chart.


The chart is dense, and the text is rather small. You can click on it to see a larger version. The top section shows the number of seconds of resistance each item presents, with one hour or more (3,600 seconds) highlighted in orange. The middle section lists the number of days, with a pink highlight for more than seven days. The lower section lists the number of years with four highlights:

  • Yellow for more than two years.
  • Blue for more than 1,000 years.
  • Green for more than one million years.
  • Pale green for more than one trillion years, what I call "quantum-ready".

For what I call "casual shopping", such as Amazon and other online retailers, the "blue edge" ought to be good for the next few years. For banking and other high-security websites, I'll prefer the darker green section. That means, using AN71, I need 13-character passwords for the thousand-year level, and 14-character passwords for the million-year level.

There is one more wrinkle to consider: The numbers shown are the time it takes a THPS machine to exhaust the possibilities at that level. If your password is "in" a certain level, it might not last that long, but it will last at least as long as the level to its left. For example, AN71 of length 12 shows 520 years. Not bad. If you have an AN71 password of length 13, the cracking machine would need 520 years, to determine it isn't 12 characters or fewer, but once it starts on 13-character passwords, maybe it will take it half or more of the 36,920 years indicated to find it, but it might luck out and get there much sooner. But it still consumed 520 years getting this far. Anyway, if you're going for a certain criterion, adding a character makes it definite that at least that length of time would be needed for the hardware to get into the region in which your password resides.

Another way to boost the resistance is to have at least two special characters, one (or more) from the AN71 set, and at least one from the rest of the AN89 set, such as "-" or "~", wherever a website allows it. Then a machine that checks only within AN71 will never find it.

With all this in mind, I plan to devise a set of passwords with lengths from 13 to 16 characters, using primarily AN71. On the rare occasion where I can't use special characters, I'll have AlphaNum alternatives with 14 to 17 characters prepared. I'll test if I can use a tilde or hyphen, and use one of them if possible for the really high-security sites.

A final word about password composition. I actually use pass phrases with non-alpha characters inserted between words or substituted for certain letters, and occasional misspellings. Starting with a favorite phrase from Shakespeare, Portia's opening clause, "The quality of mercy is not strained", one could pluck out "quality of mercy" (16 characters) and derive variations such as:

  • qUal!ty#of#3ercY
  • QW4lity70f8M&rcy
  • quality$of~MERC7
  • qua1ity2of2M3rcyy (AlphaNum with an appended letter)

…and I could add more than one character in place of the space(s) between words…

It is also worth keeping abreast of news about quantum computing. What exists today is dramatically over-hyped. It may not always be so. But I suspect a trillion-year-resistant password will remain secure for at least a generation. 

Thursday, April 26, 2012

Staying connected

kw: computer security

I haven't had a reason to visit the FBI web site before, but a newspaper article gave me one. Some clever cybercriminals set up a web server warehouse in Eastern Europe and propagated a virus that caused computers to send internet page address requests to their data warehouse to be resolved. The page addresses returned had more ads or different ads than the "normal" page. The scam owners made a few millions from the ad agencies they favored in this way.

To take down this operation, which amounted to infections of at least half a million computers worldwide, the FBI contracted a company to set up a mirror site running the same server software, then arrested the Eastern Europeans and closed down the original site. This has been going on for months now, but the mirror site is about to be closed down, on July 9 (don't you love how judges pick dates?). From that date, an infected computer will be unable to access the internet at all, because it will be sending requests to a set of Domain Name Servers (DNS's) that no longer exist. One side aspect of the infection is that antivirus updates are blocked, so other malware has probably infected the computer.

The FBI's contracting company has a tool to detect an infection, and a procedure to remove the infection if it is found. There are a couple of web addresses being printed in newspaper articles. I decided to go through the FBI and see what they offered. First, I checked my computer to see if an antivirus update would work. It did, so I had some initial comfort that I was unlikely to be infected.

To do what I did, do the following:
  • Enter the URL www.fbi.gov . I haven't provided a link here because it is safest if you type in the URL directly.
  • At the upper right they have a search bar. Enter dcwg; you are looking for articles about the Domain Change Working Group, the contractor working with the FBI.
  • From the list returned, the second or third link will be to a page "Check to see if your computer is using rogue DNS". Click on that.
  • There is a set of links. Which one you use depends on where you are in the world, and your language. Click one of them.
  • You will then see either a green box or a red box. The green box tells you your computer is OK. The red box informs you how to remove the infection it found. I haven't had to do so, so you are on your own from here.
I thought of using some screen shots in this item, but decided they could too easily be used to promulgate a meta-scam. Sometimes good old-fashioned text is best.

Tuesday, April 03, 2012

Make a million-year password

kw: computer security, passwords, analysis

An online bank recently had all its clients upgrade their passwords. In the past, passwords were 4- to 6-digit numbers. Now they have to be an 8- to 10-digit number. Taken at face value, a 10-digit password is not very secure. It has only ten billion possible values, and a special-purpose computer built for cracking encrypted passwords (known as "hashes") can try all ten billion in a tenth of a second. What makes this site more secure is that the password must be entered via a special translation screen that converts it to some kind of text, and it is the text that they check when you are logging in.

Banks and brokerage companies have been slow to attain useful levels of security, but they are getting there. I am rankled by the limit many of them have of ten characters for the length of a password. It is barely adequate, as this chart shows:

Here, based on the number of character strings of each type, we see how long the fastest known machine can try all possible combinations. For example, consider ten characters, limited to upper and lower case letters. There are 5210, or 1.45x1017 possible strings to check. At 1011 per second, the process takes 1.45 million seconds, or 16.7 days.

On average, a password will be found somewhere in the middle of the process. Thus a password such as PlentyHard, or pLeNtYhArD, may take seven or eight or nine days to crack. If you are lucky, it'll take longer; if the cracker is lucky, it might be found almost immediately. Depending on the strategy used by the software, shorter combinations will have been tried already, which might take eight hours, or as much as eighteen. So you see it is necessary to go one step further, either down or to the right, to ensure that at least this level of difficulty is presented to a cyber criminal.

For example, changing a few characters to digits puts you in the next column, such that the full 16.7 days must pass first, before the program tries the next set, which can take three months to crack. But adding a character is much better: PlentyHardy gets into a set that takes 2.4 years to scan, and PlentyHard7 boosts that to 16.5 years, with the 2.4 years as a minimum that has to be got through before the software even tries strings that contain a digit or two.

Here's the rub. Moore's Law for computer power isn't over yet. At present, maximum speed is doubling about every three years. That means that in thirty years, the fastest password cracking machine might be able to check 100 trillion combinations per second. That cuts a 2.4 year task down to under a day. PlentyHard7 just isn't hard enough any more. To be really secure, we need to use passwords that are of thousand-year grade today, so they'll last a while. Even better, let's get into the red territory on the chart above, passwords that will withstand attack for a million years at the 100 billion-per-second rate. They'll still be proof against attack at the kiloyear level in 2040.

Some possibilities:
  • A single-case password with at least 19 characters (e.g. tumblingtumbleweeds)
  • A lower-case-plus-numeric password with 17 characters or more (e.g. dr1ft1nga7ongw1th)
  • A mixed-case password with 16 or more characters (e.g. RoundTHEMountain)
  • A mixed-case-plus-numeric password with at least 15 characters (e.g. Sh3778be8C0m1ng)
While you could save one more character by adding some punctuation, it is hardly necessary. A long, mixed-case password is plenty good enough.

You can see from my examples that I like to use song titles or lyrics and modify them with case shifts and digit substitutions. I am required at work to use at least one punctuation mark, so I might choose Sh377$be$C0m1ng, which can hold off the cracker for billions of years, at present. It is likely to remain secure throughout the 21st Century.

The whole applecart might get upset if quantum computing becomes useful. To crack a password, however, the set of N qubits will have to hold an entire set of hashes of length N. Just getting four values into a qubit has yet to be reliably achieved. Getting more than two qubits to coordinate has also yet to be achieved. Quantum-tronics is quite a bit harder than electronics! But if a quantum computer could set up a string of N qubits with trillions of distinguishable states, a password's hash of size N would be cracked in a single machine cycle (some fraction of a billionth of a second).

If this becomes a reality, we'll be forced to return to banking the old way, with brick-and-mortar branch offices staffed with armies of tellers, handling transactions manually. Even the telephone might be suspect, as programs get better at simulating human interaction. Some things about the good old days are still good.

Tuesday, January 24, 2012

Cyber construction

kw: observations, computers, computer security

I've been reading a book about computer hacking, the criminal kind. I find it remarkable just how easy it is. Most of the exploits we've read about have, as their underlying secret, a bit of social engineering. Someone got talked into revealing a password. In any operating system, there are a great many vulnerabilities, but it is typically easier to deceive someone to get access. Our human monitors need our support, because they are both the strongest and the weakest link.

There are problems in general with writing computer software. Computer code is remarkably fragile. A programmer (or programming team) has to think of literally everything that the program may be faced with, and write specific code to respond appropriately. A saying has been going around for years: "If we built houses the way we write computer programs, the first woodpecker that came along would destroy civilization."

I realized why this is so: the materials of construction do not have innate properties that help a program builder achieve his or her objective. If you build a house using stone or brick, the characteristics of the materials automatically assure a basically secure structure. You don't have to worry about (most) people blasting their way in through the wall, you just have to worry about making the doors and windows secure. Think of the three little pigs. The only weak point in the brick house was the chimney, and it was small enough to be defensible.

People have been learning how to build with stone, brick, wood and other materials for thousands of years. It was largely a matter of learning which material has what properties. Computer code has no intrinsic properties that can help you. We have been building software for only about seventy years (except for Ada Lovelace, who wrote software in the 1840s). We have no "stones", so we have to invent them. Software libraries provide building blocks that make programming easier, but there is still a problem. Most of those "building blocks" are still made of "jello". We haven't truly thought of everything yet.

This is because computer code is inherently bosonic, rather than fermionic. A digression into particle physics is needed:
  • Bosons obey Bose-Einstein physics and, in particular, can pass through one another; many can occupy the same space simultaneously.
  • Fermions obey Fermi-Dirac physics and, in particular, cannot pass through one another, but bounce off one another; two fermions cannot occupy the same location.
Light is made of bosons called photons. Matter is made of fermions such as protons, neutrons and electrons.

In cyberspace, everything is bosonic unless you specifically write fermionic properties for it. An environment such as Second Life has to be very carefully written, with a good "Physics package" to ensure that you don't walk through a wall. Otherwise, walking through walls is the norm. Buildings would not need doors. Our best security software is an attempt to produce a solid door. Sadly, even the best "firewall" software is a bit softer than the average piece of Balsa wood. If you can't prevent a break-in, you at least have to make the firewall "noisy" so it lets you know when it was broken through.

At my company, a double-layered firewall scheme is used, with plenty of very "noisy" alarms to log entry attempts (or entries), but the key to keeping our environment secure is a large contingent of people who spend all day, every day monitoring the noisemakers and snooping on the incoming traffic. Intrusions still occur, but it's a crack team; not much gets by them, and never for very long.

Thus, people are still the key to good security. Imagine if the front door to your house was made of rice paper (like the internal walls of Japanese houses). You'd need a hired team of bodyguards to keep strangers out. People are fermionic; things bounce off and stuff can't pass through unnoticed.

Until our software libraries include truly bullet-proof code, we'll continue to need human monitoring of everything. That's why you need to have strong passwords (ten or more characters, MiXed CasE and with numb3r5, at the very least), but you also need to monitor your accounts and keep good relations with the folks at the other end who are tasked to also monitor things. A skilled social engineer may get past a company monitor, but if those monitors know you are watching, they are less likely to give in to the blandishments of a fast-talking impersonator.

Jesus said, "When a strong man, fully armed, guards his own house, his possessions are safe, But when someone stronger attacks and overpowers him, he takes away the armor in which the man trusted and divides up his plunder." A hint: hackers are clever, but not strong. Guard your own stuff.

Wednesday, June 24, 2009

Don't dump old drives!

kw: observations, recycling, computer security

A local PBS station, WHYY in Philadelphia, had a segment on Frontline/World last evening about e-waste and electronics recycling. When old electronics go to a "recycler", they are likely to wind up in a place such as Ghana or southern China, where two main industries flourish on our waste.

Firstly, the metals are reclaimed. This is done by burning the plastics off the metals and reclaiming iron and copper. Magnets from old speakers are used to sift through debris for iron bits that would otherwise be missed. Circuit boards usually get special treatment: they are cooked to remove the chips, which often contain gold in their traces (internal wiring) or contacts.

Secondly, the disk drives are put up for sale. Some are used to upgrade local computers, but many are plundered for their remaining data. Even if the files have been "erased", their content is still sitting on the disk, and "file recovery" or "unerase" programs can reconnect the data with the file's header in the folder. There was a disturbing sequence showing how easy it was for a technician to read personal information from a discarded hard drive.

People, if you are going to discard an old computer, first go to fileshredder.org and download FileShredder. Run it against everything it will let you shred. Then it might be safe to discard the hardware. If you want to be really sure, remove the hard drive and either keep it or remove its top and pour in a spoonful of Comet® cleanser (abrasive)…or just smash the platters with a hammer.

These are some of the old disk drives I've kept. Their sizes are 40Mby, 511Mby, and 2.5Gby, from left to right. I took the top off the 511Mby one to show the platters and reading head. In the closeup below you ought to be able to see that this one has two platters. There are four heads to cover the four surfaces on which data goes.

Back when 40Mby was a lot of disk, I managed to fill the first one pretty full. I haven't opened it to see how many platters there are, but I suspect it is either three or two. I find it amazing that my son just bought, for less than $100, a disk drive that holds a Terabyte; that's 25,000 times the capacity. One drive I don't show is a disk pack from a CDC 6400, a removable pack that holds 50Mby; it is more than a foot in diameter and seven inches tall. I'm pretty safe with it; the drive needed to read it doesn't exist any more.

Before I stopped using each computer, I copied all the data to its replacement machine. We have one more old machine that we will discard, maybe soon. I've already copied the data to a newer machine's secondary drive. I've gotten smarter over the years, and now keep most data on an external drive. Whenever I move a block of files to it, I back them up to a DVD. That way I have all our documents since we began using home computers in the early 1980s. But I don't let copies of old data get out of doors! And neither should you!!

Monday, June 13, 2005

Schneier on Security: Attack Trends: 2004 and 2005

kw: computer security, digital arms race

Have a look at this post by Bruce Schneier:
Schneier on Security: Attack Trends: 2004 and 2005

We have reached a situation in which our machinery is subject to the same threatening environment as any biological species. Both pathogens and immune systems—of the digital persuasion—are in an arms race that will spiral onward, probably without limit.

It may seem that there is a conceptual difference: computer viruses, worms, and spyware (and other varieties even now being ideated) are produced by programmers. To my way of thinking, the worm-writer is a part of the system, and bears the same relationship to the software that an animal body and mind bear to the selfish DNA upon which their existence depends.