The Number That Makes the Rest Necessary
Last timeNever Store the Password
Put a real figure on how many guesses a rented machine makes per second against a fast one-way value, and every precaution in this course stops looking like ceremony.
Guesses per second
A fast one-way function is fast. That sounds tautological and it is the
whole problem, because the function was designed to be computed quickly on
ordinary hardware, and that design goal serves the attacker exactly as
well as it serves you.
You compute it once per login. They compute it once per candidate, and
they have the whole table, so they compute it once per candidate per
account, except that without the per-user value from the next lesson they
do not even need to do that.
The rate on commodity hardware is in the billions per second for a single
rented graphics card, and nothing stops somebody renting several. That is
not a specialist capability. It is an hourly rate on a public price list,
which brings it inside the budget of every attacker in the lesson on who
would bother.
- seconds to find the password
- guesses required, which is not the size of the space but the position of the password in the attackers ordered list
- guesses per second, which is a property of the function and the hardware
How big the space is
The conventional way to argue about password strength is to compute the
size of the space: the number of available characters raised to the
length. Ninety-five printable characters to the power of eight is around
six and a half thousand million million.
Divide that by a rate of ten thousand million guesses a second and you get
about a week, which sounds reassuring and is one of the most misleading
figures in the subject.
| space size suggests safe | actually safe, 0 to 3 | appears early in the att | survives a week of guess | |
|---|---|---|---|---|
| a word from a dictionary | 3 | 0 | 3 | 0 |
| a word with a digit afte | 3 | 0 | 3 | 0 |
| a word with a digit and | 3 | 1 | 3 | 1 |
| two words joined, with a | 3 | 2 | 2 | 2 |
| a short random string | 1 | 3 | 0 | 3 |
| a long random string fro | 3 | 3 | 3 | 3 |
The arithmetic is right. The assumption is wrong, and the assumption is
that the attacker searches the space. Nobody searches the space. Searching
the space is the method of last resort, used only after everything else
has failed, and for most tables it never gets there because it did not
need to.
The lesson stops here
4 more paragraphs to go
You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.
The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.
See the planThe contentsThis is the reading half
Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.
The contents