{"id":78498,"date":"2015-11-11T21:13:49","date_gmt":"2015-11-12T02:13:49","guid":{"rendered":"http:\/\/rbach.net\/blog\/index.php\/"},"modified":"2021-11-28T16:11:03","modified_gmt":"2021-11-28T21:11:03","slug":"a-new-cure-for-passwords","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/a-new-cure-for-passwords\/","title":{"rendered":"A New Cure for Passwords"},"content":{"rendered":"<p><a href=\"http:\/\/betanews.com\/2014\/07\/16\/choose-bad-passwords-and-reuse-them-often-says-microsoft\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-105438\" title=\"A New Cure for Passwords\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/password_bad2-1.jpg?resize=73%2C110&#038;ssl=1\" alt=\"A New Cure for Passwords\" width=\"73\" height=\"110\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/password_bad2-1.jpg?resize=100%2C150&amp;ssl=1 100w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/password_bad2-1.jpg?resize=50%2C75&amp;ssl=1 50w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/password_bad2-1.jpg?w=400&amp;ssl=1 400w\" sizes=\"auto, (max-width: 73px) 100vw, 73px\" \/><\/a>Regular readers of <a href=\"https:\/\/rbach.net\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Bach Seat<\/strong><\/a> know that <a title=\"Password\" href=\"http:\/\/en.wikipedia.org\/wiki\/Password\" target=\"_blank\" rel=\"nofollow noopener wikipedia noreferrer\">passwords<\/a> suck. The better a password is, the harder it is to remember. So most people just end up choosing passwords they think are safe, but are pretty bad (<strong><em>rb-<\/em><\/strong><em> I have <a href=\"http:\/\/rbachnet.wwwmi3-ss40.a2hosted.com\/index.php\/password-insecurity\/\" target=\"_blank\" rel=\"noopener noreferrer\">covered<\/a> <a href=\"http:\/\/rbachnet.wwwmi3-ss40.a2hosted.com\/index.php\/25-most-used-passwords\/\" target=\"_blank\" rel=\"noopener noreferrer\">crappy<\/a> <a href=\"http:\/\/rbachnet.wwwmi3-ss40.a2hosted.com\/index.php\/many-ex-employees-can-still-access-privileged-info\/\" target=\"_blank\" rel=\"noopener noreferrer\">passwords<\/a> many times). <\/em><a title=\"University of Southern California\" href=\"http:\/\/www.usc.edu\/\" target=\"_blank\" rel=\"homepage nofollow noopener noreferrer\">University of Southern California<\/a> researchers <a href=\"https:\/\/web.archive.org\/web\/20170610104039\/http:\/\/www-scf.usc.edu:80\/~mghazvin\/\" target=\"_blank\" rel=\"noopener noreferrer\">Marjan Ghazvininejad<\/a> and <a href=\"https:\/\/web.archive.org\/web\/20231225120311\/https:\/\/www.isi.edu\/~knight\/\" target=\"_blank\" rel=\"noopener noreferrer\">Kevin Knight<\/a>, have come up with a new solution that they believe solves the crappy password problem.<\/p>\n<p><a href=\"http:\/\/hothardware.com\/news\/elcomsofts-internet-password-breakers-scares-the-crap-out-of-us\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-105440\" title=\"unique solution for creating passwords\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Password_Dog-6.jpg?resize=133%2C100&#038;ssl=1\" alt=\"unique solution for creating passwords\" width=\"133\" height=\"100\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Password_Dog-6.jpg?resize=150%2C113&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Password_Dog-6.jpg?resize=75%2C56&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Password_Dog-6.jpg?w=500&amp;ssl=1 500w\" sizes=\"auto, (max-width: 133px) 100vw, 133px\" \/><\/a>The USC researchers&#8217; paper \u201c<a href=\"http:\/\/www.isi.edu\/natural-language\/mt\/memorize-random-60.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">How to Memorize a Random 60-Bit String<\/a>\u201d (PDF) presents a unique solution for creating passwords that are hard to crack and relatively easy to remember: <strong>randomly generated poems<\/strong>.<\/p>\n<p>The researchers believe that the most secure and memorable method for creating a strong password is a <strong>short rhyming poem of random words<\/strong>. The <a href=\"https:\/\/web.archive.org\/web\/20151029230402\/https:\/\/www.washingtonpost.com\/news\/wonkblog\/wp\/2015\/10\/22\/these-researchers-have-discovered-the-perfect-password-thats-also-easy-to-remember\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Washington Post<\/em> explains<\/a> that, even if you pick a fairly uncommon word, like &#8220;Troubadour,&#8221; and replace some of the letters with other symbols, this combination might only take a computer seconds, minutes, or hours to guess.<\/p>\n<p><a href=\"http:\/\/blogs.cccb.org\/lab\/en\/article_tecnorevolucio-a-les-aules\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-105442\" title=\"short rhyming poem of random words as a\u00a0password\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/calculatingmachine.jpg?resize=148%2C70&#038;ssl=1\" alt=\"short rhyming poem of random words as a\u00a0password\" width=\"148\" height=\"70\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/calculatingmachine.jpg?resize=150%2C71&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/calculatingmachine.jpg?resize=75%2C35&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/calculatingmachine.jpg?w=635&amp;ssl=1 635w\" sizes=\"auto, (max-width: 148px) 100vw, 148px\" \/><\/a>The idea of a short rhyming poem of random words as a password might seem a little odd, but they&#8217;re actually very, very secure according to USC&#8217;s Knight. At current speeds, he estimates that cracking these rhyming poems of random words passwords would take around 5 million years. By which point, we probably won&#8217;t be using Facebook anymore.<\/p>\n<p>As part of their research, the USC team created their poems by assigning every word in a 327,868-word dictionary a distinct code. The article explains they then use a computer program to<strong> generate a very long random number<\/strong>, like<br \/>\n110111000111100100100010100010101100001100010000010010100100, and<b> <\/b>break that number up into pieces, and then translate those pieces into<strong> two short phrases<\/strong> of four or five words. The computer program they use ensures that the two lines end in words that rhyme and that the phrase is in <a title=\"Iambic tetrameter\" href=\"http:\/\/en.wikipedia.org\/wiki\/Iambic_tetrameter\" target=\"_blank\" rel=\"nofollow noopener wikipedia noreferrer\">iambic tetrameter<\/a>, like so:<\/p>\n<p>A techno salmon Benedict<br \/>\n<a href=\"https:\/\/streambase.typepad.com\/streambase_stream_process\/2010\/01\/9-predictions-for-event-processing.html\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-105444 size-medium\" title=\"Even Shakespeare had problmes with laptops\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/shakesphere_laptop.jpg?resize=150%2C121&#038;ssl=1\" alt=\"Even Shakespeare had problmes with laptops\" width=\"150\" height=\"121\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/shakesphere_laptop.jpg?resize=150%2C121&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/shakesphere_laptop.jpg?resize=75%2C61&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/shakesphere_laptop.jpg?w=320&amp;ssl=1 320w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a>performing under derelict<\/p>\n<p>or:<\/p>\n<p>The baby understand curtailed<br \/>\na wooden synagogue prevailed<\/p>\n<p>or:<\/p>\n<p>The Oracle email update<br \/>\nequipment pinning demonstrate<\/p>\n<p><strong><em>rb-<\/em><\/strong><\/p>\n<p><em>While seemingly nonsensical quips like\u00a0<\/em><\/p>\n<p style=\"text-align: center;\"><em>Whereas Chanel control McQueen <\/em><br \/>\n<em>accusing glamour magazine<\/em><\/p>\n<p><em>don&#8217;t make a lot of sense to 21st-century humans, we should be able to recall 7 or 8 words to better protect our personal information. \u00a0The oral record is how most information passed from human to human for generations before <a href=\"https:\/\/en.wikipedia.org\/wiki\/Johannes_Gutenberg\" target=\"_blank\" rel=\"noopener noreferrer\">Guttenberg<\/a>. Someone told you something and you remembered it. There are a number of oral traditions that have lasted in one form or another into the 21st century.\u00a0<\/em><\/p>\n<p><em>One big problem with the rhyming poem of random words idea is the webserver operating systems. There are a number of web servers out there that cannot take passwords longer than 12 characters. <strong>Hey, webmasters wake up<\/strong> &#8211; <strong>Update your operating systems<\/strong>.<\/em><\/p>\n<p><em>The researchers have set up an online generator for these poem\/password, which you can <a href=\"http:\/\/www.isi.edu\/natural-language\/people\/poem\/poem.php\" target=\"_blank\" rel=\"noopener noreferrer\">try here <\/a>or you can enter your <a href=\"https:\/\/web.archive.org\/web\/20190216182123\/http:\/\/52.24.230.241\/bc\/password_generation.php\" target=\"_blank\" rel=\"noopener noreferrer\">e-mail here<\/a>, and their program will send you a poetic password.<\/em><\/p>\n<h6>Related articles<\/h6>\n<ul>\n<li><a href=\"https:\/\/www.insidehighered.com\/quicktakes\/2016\/02\/24\/what-if-e-network-covered-engineering\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">What If the E! Network Covered Engineering?<\/a> (insidehighered.com)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Passwords suck and USC boffins say poems can replace shady passwords<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3277,2541,2574,4,1117,2575],"class_list":["post-78498","post","type-post","status-publish","format-standard","hentry","category-security","tag-3277","tag-passwords","tag-poetry","tag-security","tag-shakespeare","tag-usc"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/78498","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=78498"}],"version-history":[{"count":9,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/78498\/revisions"}],"predecessor-version":[{"id":130899,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/78498\/revisions\/130899"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=78498"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=78498"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=78498"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}