Παρασκευή 12 Δεκεμβρίου 2014

Diceware: Random Passphrase Generator


You hear all the time that it is crucial for your online security to build a strong password. We have previously outlined the guidelines for a "good" password but sometimes this is not enough. Applications such as e-mail and data encryption, bitcoin wallets and password managers require a grater degree of protection. Securing such applications with a long complex password might just not be enough. Hardly anyone can remember such a password and most of us will write it down to a piece of paper, compromising the entire effort.

Passphrases can be an alternative to this. A passphrase is a bunch of words and characters that you type in to your computer to let it know for sure that the person typing is you. Most newer security programs allow you to enter a passphrase instead of just a short password for added protection against attackers. Some programs also use your passphrase to form a cryptographic key to encrypt your data. Passphrases differ from passwords only in length. Pass words are usually short - six to ten characters. Their greater length makes passphrases more secure. Modern passphrases were invented by Sigmund N. Porter in 1982.

Picking a good passphrase is one of the most important things you can do to preserve the privacy of your computer data and e-mail messages. A passphrase should be:

  • Known only to you
  • Long enough to be secure
  • Hard to guess - even by someone who knows you well
  • Easy for you to remember
  • Easy for you to type accurately
Diceware™ is a method for picking passphrases that uses dice to select words at random from a special list called the Diceware Word List. Each word in the list is preceded by a five digit number. All the digits are between one and six, allowing you to use the outcomes of five dice rolls to select one unique word from the list. The complete list contains 7776 short English words, abbreviations and easy-to-remember character strings. The average length of each word is about 4.2 characters. The biggest words are six characters long.

There are though some important steps to follow before using this method to create a strong passphrase.

  1. You need a regular six-sided dice
  2. You should download the Diceware word list in English or any other language of your choice. Diceware lists are available for Chinese, German, Esperanto, Spanish, Finnish, French, Italian, Japanese, Dutch, Polish, Russian, Swedish and Turkish
  3. Decide how many words you want in your passphrase. A five word passphrase provides a level of security much higher than the simple passwords most people use. We recommend a minimum of six words for use with Hushmail, wireless security and file encryption programs. A seven or eight word pass phrase is recommended for high value uses such as BitCoin, and the like.
  4. For each word in your passphrase roll five times the die. (ex. for a six words long passphrase you need to roll 30 times).
  5. Look up each five digit number in the Diceware list and find the word next to it. (ex. 54321 is word slain).
  6. Once done you should have a list of words that correspond to your passphrase. Memorize them and destroy any evidence of creation.
Recommendations
Because some words on the diceware list are two characters or less, you can get a very short passphrase. If your passphrase, including the spaces between the words, is less than 17 characters long, it is highly advised that you start over and create a new passphrase. You should also start over if your passphrase is a recognizable sentence or phrase. (These situations are very rare.)
Do not use a random number generator! Such utilities are rarely truly random. Just roll the dice.

Extra Option
For extra security without adding another word, insert one special character or digit chosen at random into your passphrase. Here is how to do this securely (example given for a 6-word long passphrase): Roll one die to choose a word in your passphrase, roll again to choose a letter in that word. Roll a third and fourth time to pick the added character from the following table:

Dice rolls 1 2 3 4 5 6
1 ~ ! # $ % ^
2 & * ( ) - =
3 + [ ] \ { }
4 : ; " ' < >
5 ? / 1 2 3 4
6 5 6 7 8 9 0




Some math: (click to expand) It is usual in the computer industry to specify password strength in terms of information entropy, measured in bits, a concept from information theory. Instead of the number of guesses needed to find the password with certainty, the base-2 logarithm of that number is given, which is the number of "entropy bits" in a password. A password with, say, 42 bits of strength calculated in this way would be as strong as a string of 42 bits chosen randomly, say by a fair coin toss. Put another way, a password with 42 bits of strength would require 242 attempts to exhaust all possibilities during a brute force search. Thus, adding one bit of entropy to a password doubles the number of guesses required, which makes an attacker's task twice as difficult. On average, an attacker will have to try half of the possible passwords before finding the correct one.

Each word created with the Diceware™ method has 12.9 bits of entropy (log2(7776)), thus a 6-word passphrase yields 77.5 bits of entropy and a 7-word passphrase a 90.4 bits, and so on...
A 16-character long random password [a-z][A-Z] yields 5.7 (log2(52)) bits per character, thus 91.2 bits, slightly more than a 7-word long passphrase. Inserting a letter at random adds about 10 bits of entropy.
Axiom
Passwords of equal entropy are considered equally secure.

So why use the Diceware™ method? The answer is that it is far more easy to remember six (or more) lowercase common words than to remember a 16-character long stream of random characters.

A large number of password generator programs and websites are available on the Internet. Their quality varies and can be hard to assess if there is no clear description of the source of randomness that is used, and if source code is not provided to allow claims to be checked. Furthermore, and probably most importantly, transmitting candidate passwords over the Internet raises obvious security concerns, particularly if the connection to the password generation site's program is not properly secured or if the site is compromised in some way. Without a secure channel, it is not possible to prevent eavesdropping, especially over public networks such as the Internet. A possible solution to this issue is to generate the password using a client side programming language such as JavaScript. The advantage of this approach is that the generated password stays in the client computer and is not transmitted to or from an external server. JavaScript Password Generator is an example of such a site.

Πέμπτη 11 Σεπτεμβρίου 2014

List of 5 Million 'Gmail Passwords' Leaked

A list of almost five million Gmail addresses and passwords culled from various websites was posted on a Russian online forum Tuesday.
Mashable and other technology news websites reported that the leaked passwords are not necessarily those used to access Gmail accounts but seem to have been compiled from other websites, including some where Gmail addresses were used to register.
Several internet security experts who examined the leaked list, which was posted as a text file to the Russian online forum Bitcoin Security, reported on Twitter that the passwords appear to be several years old. Danish cybercrime specialist Peter Kruse of the CSIS Security Group tweeted that the leak "likely originates from various sources" and that most of the leaked passwords are more than three years old. Even if this dump is simply a collection of old passwords belonging to minor sites, the issue is always the same: password reuse. If you tend to reuse your passwords, stop doing this.

Τρίτη 9 Σεπτεμβρίου 2014

InfoSec Essentials: Passwords

Passwords: Who needs them?
How many keys do you carry with you every day? Personally, I hold about 5-7 regularly, home, office, car not counting any remote controls such as garage or car alarm. Why is this? Why don’t we have a single key to have access in all locations? I believe that all of you can deduce the answer. The same is true about passwords. Passwords are the digital keys that allow us to access what is ours, our e-mail, our bank account, our files in the cloud.
Would you ever give the keys of your house to a stranger. If the obvious answer is no, then why write your password in your journal or even on a post-it on your monitor, it's like hidding your keys under the door carpet.

P4s$w0rd-c()Mp1exiTy
Why on Earth should I create a 10 characters long alphanumeric password? The key example also works here. How would you feel if the lock of your home could be picked with a screwdriver or even a hair pin? The key complexity is analogous to the password length and charachter composition, so stop whining when you read the password rules and build some strong passwords for your accounts.
Earlier this year SplashData, published a list of the 25 worst passwords of 2013. You should notice that out of the 25 entries, none fulfills the basic requirements of a strong password. I whould say that most of them don't even classify as weak.
Trivia: Back in the 90s the four most common passwords where sex, God, love and secret.

Multi Factor Authentication
Multi-factor authentication (MFA) is an approach to authentication which requires the presentation of two or more of the three independent authentication factors: a knowledge factor ("something only the user knows"), a possession factor ("something only the user has"), and an inherence factor ("something only the user is"). After presentation, each factor must be validated by the other party for authentication to occur. The most common implementation of MFA, is two-factor authentication used by various services through the web, such as google services, apple services, ebay, evernote etc. There are various tutorials in the web to assist you enabling this feature, just use your favorite search engine.

Never take candies from strangers or “fear the Danaans, even those bearing gifts”
Do you remember your parents advise you not to take gifts from strangers? The same applies to cyberspace and is not restricted to children. Fake emails is the most common way of a type of attack called social engineering in order to collect information or an easy way to spread malware. The attacker sends bulk emails to the victims, commonly with an attachment that hides the true nature of the message. Most companies try to train their users not to trust emails that pretend to be from legit source and ask them to share personal/private information or PIN numbers but despite the awareness campaign, many users still fall victims of this malicious practice. So please stop opening these funny video links from unknown senders, the “!!!FREE GIFT!!!” that you have never asked for and stop providing your account number and e-banking password to the bank via email, no one but the attacker cares for this info. Sometimes, all the attacker seeks is just email addresses in order to lunch a spam campaign. By forwarding e-mails like "..mail this to all your friends to reach total happiness..." or "unless you forward this message bad luck will fall upon you..", collectively known as chain letters, you just help the attacker, so please stop forwarding these emails to your entire contact list.