The Macrosite for News, Analysis and Opinion about the Future of the Internet
Stephen Lawton

The Case of the Cracked Password

Written by Stephen Lawton
1/8/2013 26 comments
DISCUSS     Email This

Debates rage over how complex a password should be, but today some are questioning if passwords themselves are obsolete. Security consultants tell us that the longer the password and more complex it is, the harder it is to compromise. This might well be true against an attacker who is trying to break a password by hand, but against technological powerhouses, keyboard-based passwords may be insufficient.

There are two considerations here that need to be addressed. The first, of course, is the password the user creates for his personal websites and files. These passwords often are designed for the user to remember and often are repurposed for multiple sites. There are myriad articles that explain password-cracking techniques, but far too often users simply pick the easiest key combinations they can remember. Worse, sometimes people use these combinations for sites that contain sensitive data, such as banks or healthcare organizations.

What not to choose.
(Source: Uniblue)
What not to choose.
(Source: Uniblue)

Today’s prevailing wisdom is to create a password that combines upper- and lower-case letters with numbers and special characters, such as ^, ?, <, or }. The challenge, however, is that some websites and applications are unable to handle special characters, so that significantly reduces the potential complexity of the passwords. Additionally, ASCII characters (created using a combination of the ALT key and a numeric code, such as the British Pound symbol £ produced by holding down the ALT key and typing 0163) also are excluded from many password applications.

The second consideration is how companies encrypt user logins and passwords. Many of today’s sophisticated password applications are capable of using the much more complex password combinations. Various algorithms (called the “hash function”) are used to encrypt data, which then creates a “digest” that represents the data being stored. If that digest is stored in a database of user credentials, it becomes a valuable commodity to an attacker. The more complex the hash function, the longer and more difficult it is to decrypt the data.

In order to demonstrate the weaknesses in existing data security techniques, Jeremi Gosney, founder and CEO of Seattle-based Stricture Consulting Group, built and demonstrated a system designed to crack any eight-character password created on a standard, US-style keyboard using any key combination, in less than six hours, using a brute force attack. Gosney demonstrated the system’s capabilities at the Passwords^12 Security Conference in Oslo in December.

Using a custom design created by Amnon Barak and Amnon Shiloh at Hebrew University, the system is based on a cluster of 25 graphics processors running Virtual OpenCL. This approach, Gosney tells Internet Evolution, makes the system relatively inexpensive to build and optimize for the task at hand. This is not a commercial computer; it is a purpose-built system designed to crack passwords as quickly as possible.

Gosney says popular Windows encryption hashes, such as Microsoft’s NT LAN Manager (NTLM), can be breached more quickly than other approaches, such as sha512crypt, an approach supported by Linux distributions. The idea here is not to pick on one vendor or another, he says, but rather to encourage all to support passwords that are more difficult to breach.

There are valid business reasons to be able to crack passwords, Gosney says. Corporations can use a system that can analyze millions of passwords quickly to audit their own users’ passwords, identifying those passwords that are easy to breach (such as 123456). Once an organization identifies easy-to-breach passwords, a company can contact those users and direct them to employ more complex passwords, which will make it harder for a less sophisticated attacker to guess the user logins to a corporate system.

Also, Gosney notes, users tend to reuse passwords for multiple sites. A user with a weak password probably uses that same password often. Identifying weak passwords should be part of every company’s security plan.

You can find details of Gosney’s presentation and a technical explanation of the system here.

— Stephen Lawton is a longtime technology journalist and industry pundit.

Related posts:

DISCUSS     Email This
Current display:       newest comments first       display in chronological order
Page 1 of 3   Next >
DavidSilversmith
Thinkernetter
Thursday January 24, 2013 9:59:52 PM
no ratings

I've participated in several projects where the IT department ran basic freeware/publicly available password cracking tools.  

These tests can make even a seasoned IT professional cry.

You set rules. You train.  Your encourage changes.  You explain the importance of security.

Then is under 5 seconds you crack dozens of passwords, including some from the very IT team that sets the rules and does the security training.

Mashka
Researcher
Saturday January 19, 2013 5:10:07 AM
no ratings

Briefly speaking, it means- doesn't matter how complicated your passord is, if someone wants to break your data, he/she will do that- is that correct?

stotheco
IQ Crew
Tuesday January 15, 2013 6:14:16 AM
no ratings

I find myself doing the same thing a lot lately. Either I have way too many accounts that I have to keep track of at this point, or I'm just getting old. I have since resorted to listing down passwords (which have grave consequences when I forget them) on my smartphone and save that file with a password as well. At least I just have to remember one. I know the risks involved, but it's just too hard to remember all of them at any given time!

Stephen Lawton
Thinkernetter
Saturday January 12, 2013 9:25:01 PM
no ratings

Keeping track of passwords is a real pain, Sharon. I've tested some of the password apps -- Dashlane and LastPass -- and find that these are pretty good, if you go in and tweak the default settings a bit. I'd never remember the passwords these apps generate (I've set the default to 12 characters, although I'm thinking an odd number might be better) but even still, if for some reason the app crashes or the company goes out of business, I'm up the creek without a paddle unless I back up all of the unencrypted passwords. And if I do that, I just defeated the whole purpose of having encrypted passwords.

 

slfisher
Thinkernetter
Saturday January 12, 2013 8:46:42 PM
no ratings

is, "Don't use a password you've used X times before, or in the previous X months." So I have to keep coming up with new ones, which are then harder to remember for next time, which means that, more than likely, I'll have to generate *another* new password for that site the next time I use it, which may be a month or more in the future.

I'm really trying to avoid the passwords-on-a-sticky situation, but it's getting harder and harder.

DrT
IQ Crew
Friday January 11, 2013 6:47:49 PM
no ratings
I hope that was not the one hanging on the monitor or sticked under the keyboard (as if it makes it more hidden). Picture password will hopefully help unless they take the picture of the picture password and stick it to the side of computer.
Kim Davis
Thinkernetter
Friday January 11, 2013 2:01:04 PM
no ratings

I just found out the password for something (not mine) which is supposed to be secure.  You could guess it in about three tries.  Passwords are increasingly about going through the motions.

Alison Diana
Thinkernetter
Friday January 11, 2013 1:19:40 PM
no ratings

Oh no, not going there, @magneticnorth. I have always had a thing about eyes! In fact, for about eight years I wanted to be a vet -- until I watched a documentary where a vet performed surgery on an alligator's eye. That did it. I knew I couldn't touch an animal's eye. So I guess I'll have to keep taking my vitamins or writing coded notes in order to try to recall old-fashioned passwords!!

magneticnorth
IQ Crew
Thursday January 10, 2013 9:15:11 PM
no ratings

I certainly find the frequency with which I am having to request a password re-set increasing.

Which is why I think, on a personal level at least, that the most important thing to secure is your email—the one you use for accounts. In that case, is it best to use one email address for correspondence and several different ones for online accounts? That might help spread the risk, though it'll be hell to manage so many mailboxes. Not that I don't already have more than 10 myself.

magneticnorth
IQ Crew
Thursday January 10, 2013 9:05:20 PM
no ratings

And I just want to bang my head against the wall... or invest in some biometrics.

I'm all for biometrics, though one of the first scenes on Demolition Man always makes me feel icky.

Page 1 of 3   Next >
The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
previous posts from Stephen Lawton
Stephen Lawton
Stephen Lawton   11/1/2012   3 comments
The practice of turning to end users not only to beta test but also to reengineer products -- something once widely criticized -- has reached historic levels in IT. The trend even has a new, far more benign name: crowdsourcing.
Stephen Lawton
Stephen Lawton   10/24/2012   25 comments
The issue of mobile security has IT professionals reconsidering the weaknesses inherent in Web browsers.
Stephen Lawton
Stephen Lawton   10/3/2012   8 comments
As the general election nears in the US, talk grows about how much control the government should have over how enterprises protect their networks.
Stephen Lawton
Stephen Lawton   10/2/2012   9 comments
A recent Businessweek article implies that the US Securities and Exchange Commission (SEC) is getting more aggressive when it comes to the requirement of companies to disclose material security breaches.
5
of
Mitch Wagner
TweetDeck Gets a Second Life

11|5|12   |   9:54   |   13 comments


A recent release of the popular TweetDeck app for Twitter power-users gives new life to software that had previously taken a wrong turn. Here's a quick walk-through of the new TweetDeck, to show you why it should be at the top of your Twitter toolkit.
Ann Cavoukian
Privacy Is Everyone's Responsibility

11|1|11   |   4:01   |   17 comments


Ontario's privacy commissioner offers advice to businesses and users for protecting privacy online.
Mary Maida
How Medtronic Overcomes Social Business Resistance

1|31|13   |   1:23   |   No comments


Showing results is the best way to win over social business doubters, according to Mary Maida, Medtronic lead information solutions manager. Internet Evolution's Mitch Wagner interviewed Maida at the E2 Innovate conference.
Wisdom of the Big Chair
Price, Not Features, Driving Smartphone Sales

11|29|12   |   2:01   |   7 comments


A survey by JD Powers found that customer interest in product features is lessening as phones evolve. Rather than features, price is driving purchases, and that change could have a dramatic impact on how IT departments secure these devices.
Mitch Wagner
LinkedIn Will Be the Last Social Network Standing

8|31|12   |   2:34   |   15 comments


While Facebook and Twitter get more attention, LinkedIn's going to be the long-term winner.
Reiter's Block
IT Should Evaluate On-Screen Keyboards

7|19|12   |   3:01   |   9 comments


On-screen keyboards are getting a lot more complicated, and IT departments should consider evaluating them.
Mary E. Shacklett
Law Will Define Next-Gen Privacy

4|25|12   |   1:48   |   7 comments


The plan for unmanned police drones to patrol traffic and other city conditions in Seattle has sparked a new set of legal concerns about privacy. Law traditionally lags technology, but we can expect now to see a new round of activity in the courts as legal definitions begin to emerge on what "next-gen privacy" will look like.
Beau Brendler
Terrorism Expert Says US Gave Away Stuxnet Tech

4|4|12   |   3:29   |   9 comments


US counterterrorism expert Richard Clarke, who came to prominence with his prescient warnings before the 9/11 attacks, tells Smithsonian Magazine the US was responsible for the Stuxnet supersmart worm that attacked parts of nuclear reactors in Iran – and in the process, has given away one of the world's most sophisticated cyberweapons.
Reiter's Block
Twitter Caves to Censors but Isn't the Enemy

1|30|12   |   2:49   |   13 comments


The Internet erupted in rage when Twitter said it could block tweets on a country-by-country basis. But avoid knee jerk reactions!
Kim Davis
Doublespeak on Internet Freedom

12|13|11   |   02:08   |   5 comments


Hillary Clinton stands accused of hypocrisy after speaking up for Internet freedom at a conference last week.
IETV: the thinkerNet on film
5
of
John Kennedy
How Big-Data Is Changing Marketing

6|13|13   |   1:07   |   1 comment


Big-data and analytics tools enable marketers to understand customers as individuals, identifying unmet needs and addressing each customer as a "segment of one," says John Kennedy, VP corporate marketing, IBM.
Kim Davis
Big-Data Can’t Always Sell Wine

5|21|13   |   2:23   |   10 comments


Whole Foods Global Wine Purchaser Doug Bell told me about some of the constraints on using analytics in the US wine market.
Paul J. Fleuranges
Digital Signage Keeps NYC Subway Straphangers on Track

5|6|13   |   3:51   |   1 comment


New York's Metropolitan Transit Authority is conducting a pilot test of digital kiosks to guide subway users to where they want to go more efficiently and at lower cost.
Kim Davis
Fast Forward to the Future

4|23|13   |   2:29   |   20 comments


A look back at tech writing in the 90s makes us wonder where enterprise IT will be 20 years from now.
Mitch Wagner
Google Launches Its Most Depressing Service Yet

4|15|13   |   2:59   |   10 comments


Google's new Inactive Account Manager lets you control how Google disposes of your accounts when you die.
Second Shooter
Argument Over Top-Level Domains Is 'Stupid'

4|11|13   |   2:07   |   3 comments


The whole Amazon.reader debate is a double-stupid. It's stupid to think that there's any e-book buyer who doesn't know Amazon's URL, and it was stupider to let ICANN launch the whole free-form TLD initiative to start with.
Kim Davis
Ladies, Your Tablet Awaits

3|21|13   |   2:22   |   37 comments


ePad Femme is the world’s first tablet “made exclusively for women.”
Wisdom of the Big Chair
NFC Moves Into the Mainstream

3|20|13   |   2:16   |   No comments


While NFC's original goal was to enhance mobile commerce applications, it is finding its way into a number of other uses, which is creating both opportunity as well as challenges for IT departments.
Wisdom of the Big Chair
Integrating Security Into Your Cloud Contract

3|19|13   |   3:35   |   No comments


Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
Brian Baron
How Edmunds.com Collects Customer Information

3|18|13   |   1:15   |   No comments


Edmunds separates customers into segments based on the info it collects on its site and from partners, and uses that to push out custom content, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
2pm EDT
Fri
Jun 21st
an IBM information resource
sponsored content
big blue blog
Todd Watson
Todd Watson   6/18/2013   Post a comment
The IBM Smarter Commerce Global Summit in Monaco kicked into high gear today, and we've already begun to see news emerging from that lovely city-state by the sea.
an IBM information resource
sponsored content
Expert Integrated Systems: Changing the Experience & Economics of IT
In this e-book, we take an in-depth look at these expert integrated systems -- what they are, how they work, and how they have the potential to help CIOs achieve dramatic savings while restoring IT's role as business innovator.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
Taking a Dim View of Home Energy Management Tech
Mary E. Shacklett
Energy consumption is a primary contributor to
global warming. At the end of 2012, 40 percent of energy consumption in the US came from commercial and residential buildings.

CLICK FOR MORE