HomeSecurityLorrie Faith Cranor: What's going on with your pa$$w0rd

Lorrie Faith Cranor: What's up with your pa$$w0rd

Lorrie-Faith-CranorLorrie Faith Cranor is a professor of computer science and engineering and gave a very interesting TED talk. The topic of the talk: “What's wrong with your pa$$w0rd?”

I'm a professor of computer science and engineering here at Carnegie Mellon, and my research focuses on utilitarian privacy and security, so my friends like to give me examples of their problems with computer systems, especially problems that have to do with non-utilitarian privacy and security.

So, I hear a lot about passwords. A lot of people get frustrated with passwords, and it's bad enough when you have to have a really good password that you can remember, but no one can guess it. But what do you do when you have accounts on hundreds of different systems and you have to have a unique password for each of those systems? It's hard. At Carnegie Mellon, they made it pretty easy for us to remember our passwords.

The password requirement up until 2009 was just that you had to have a password with at least one character. Easy enough. But then they changed things, and at the end of 2009 they announced that they were going to have a new policy, and this new policy required passwords to be at least eight characters long, with uppercase and lowercase letters, numbers, symbols, no more than three characters allowed, and no dictionary entries allowed. Now, when they implemented this new policy, a lot of people, my colleagues and my friends, came to me and said, "Wow, this is not useful at all. Why are they doing this to us, and why didn't you stop them?" And I said, "You know what? They didn't ask me." But I was surprised, and I decided to go and talk to our IT people and find out what made them implement this new policy. They said that the university took part in a consortium of universities and one of the requirements for participation was to have stronger passwords to comply with the new requirements.

These requirements were that our passwords had to have a lot of entropy. Entropy is a complex concept, but it basically measures the strength of passwords. The thing is, there's not really a metric for measuring entropy. The National Institute of Standards and Technology has put out some guidelines that have some rules of thumb for measuring entropy, but they're not very specific. The reason they only have rules of thumb is that they don't really have any good data on passwords. In fact, their report says, "Unfortunately, we don't have much data on the passwords that users choose under specific rules.

NIST would like to get more data on the passwords that users choose, but system administrators are understandably hesitant to disclose password data to others." So, that's a problem, but our research team saw it as an opportunity. We said, "There's a need for good password data. Maybe we can collect some good data and develop this technology. So the first thing we did was take a bag of candy and go around campus, where we talked to students, faculty, and staff and asked them for information about their passwords. We didn't say, "Give us your password." No, we just asked them about their password. What's the length of it? Does it contain numbers? Does it contain symbols? Did it bother you that you had to change it last week? So we took the results from 470 students, faculty, and staff, and yes, we confirmed that the new policy was very annoying, but we also found that people said they felt more secure with these new passwords. We found that most people knew not to write down their passwords, and only 13 percent of them did, but alarmingly, 80 percent of people said they reused their passwords. That's more dangerous than writing down your password, because it makes you much more vulnerable to hackers. So, if you have to, write down your passwords, but don't reuse them.

We also found some interesting things about the symbols that people use in their passwords. So the university allows 32 possible symbols, but as you can see, there's only a small number that most people use, so we're not getting a lot of power from the symbols in our passwords. So, this was a really interesting study, and now we have data from 470 people, but really, it's not that much password data. So we looked to see where we could find more password data? It turns out that there are a lot of people who steal passwords, and they often post those passwords online. So we were able to access some of the stolen passwords. But again, it's not ideal for research, because it's not entirely clear where these passwords came from or what policies were in place when these passwords were created. So we wanted to find a better source of data. We decided that we could do a survey and have people create passwords for our survey. We used a service called Amazon Mechanical Turk, where you can post a little task on the Internet that takes a minute, a few minutes, an hour, and you pay them a cent, ten cents, a couple of dollars, to do a task for you, and you pay them through Amazon.com. So we paid people about 50 cents to create a password with our rules and answer a survey, and then we paid them again to come back two days later and log in with their password and answer another survey. So we did that, and we collected 5,000 passwords and we gave users a couple of different policies to create their passwords. So some had a pretty easy policy, we call it Basic8, and the only rule was that your password had to be at least eight characters long.

Some had a much tougher policy that was similar to the university policy, where it had to be eight characters including uppercase, lowercase, numbers, symbols, and pass a dictionary check. Another policy that we tried, and there were many, one of the ones that we tried was called Basic16, and the only requirement here was that your password had to be at least 16 characters. Okay, now we had 5,000 passwords, and much more detailed information. Again, we see that there's only a small number of symbols that people use in their passwords. We also wanted to get an idea of ​​how strong the passwords that users were creating were, but, as you remember, there's no good measure of password strength. So, we decided to see how long it would take to crack these passwords using the best tools that bad guys use or that we could find information about in the research literature.

To give you an idea of ​​how bad guys crack passwords, they steal a password file that has all the passwords in an encoded form, called a hash, and they'll guess what the password is, run it through a hash function, and see if it matches the passwords they have in their stolen list. So a stupid attacker will try each password in turn. They'll start with AAAAA and go on to AAAAB, and that will take a long time before they find a password that someone might actually use. On the other hand, a smart attacker does something more sophisticated. They look at the passwords that they know are popular from these sets of stolen passwords and guess those first. So they start by guessing "password" and then they'll guess "iloveyou" and "monkey" and "12345678," because those are the passwords that people are most likely to have. In fact, some of you probably have passwords like that.

So what we found when we ran all these 5,000 passwords that we collected in these tests to see how strong they were, we found that the long passwords were actually quite strong, and the complex passwords were also very strong. But when we looked at the survey data, we saw that people were actually getting frustrated with the very complex passwords, and the long passwords were much more useful, and sometimes, they were stronger than the complex passwords. So that suggests that instead of telling people to put all these symbols and numbers and crazy things in their passwords, maybe it would be better to tell them to have long passwords. But the problem is this: Some people had long passwords that weren't really strong. You can make long passwords that are still something that an attacker could easily guess. So we need to do more than just require long passwords. There needs to be additional requirements, and part of our current research is looking at what additional requirements we need to add to make stronger passwords that are also easy to remember and write down. Another approach to getting people to have stronger passwords is to use a meter.

Here are some examples. You might have seen them online when you're creating passwords. We decided to do a study to find out if these password counters actually work. Do they really help people have stronger passwords, and if so, which ones are better? So we tried password counters with different sizes, shapes, colors, different words next to them, we even tried one with a dancing bunny. As you typed in a stronger password, the bunny danced faster and faster. It was fun. What we found was that password counters work. (Laughter) Most password counters are really effective, and the dancing bunny was very effective, but the most effective password counters were the ones that made you work harder before they gave you the OK and said you were doing well, and we actually found that most of the counters on the Internet today are too lax.

They tell you that you're doing well very early on, and if they had just waited a little bit longer before giving you positive feedback, you might have had better passwords. Another approach to better passwords, perhaps, is to use passphrases instead of words. This is a cartoon from xkcd a few years ago, and the cartoonist suggests that we all use passphrases, and if you look at the second line of the cartoon, you can see that the cartoonist suggests that the passphrase "right horse battery stapler" would be a very strong passphrase and something very easy to remember. He's saying, in fact, you already remember it. So, we decided to do a research study to see if that's true.

Anyone I talk to and mention that I do password research, they point out the cartoon. "Oh, have you seen that? The one from xkcd. Right, battery-powered stapler." So we did the research study to see what would actually happen. So in our study, we used Mechanical Turk again and had the computer pick random words in the password phrase. We did this because humans are not very good at picking random words. If we asked a human to do it, they would pick things that weren't so random. So we tried a couple of different conditions. In one condition, the computer picked from a dictionary of very common words in the English language, so you would have password phrases like "try there three come." And we looked at that, and we said, "That doesn't seem very memorable." So then we tried to pick words that came from specific parts of speech, what about noun-verb-adjective-noun. That comes out kind of like a sentence. So you can have a catchphrase like "plan builds sure power" or "end identifies red medicine." And those seemed a little more memorable, and maybe people would like those a little more. We wanted to compare them to passwords, and we had the computer pick random passwords, which are nice and short, but as you can see, they don't seem very memorable. Then we tried something called a pronounceable password. Here the computer picks random syllables and puts them together so you have something that you can kind of pronounce, like "tufritvi" and "vatasabi." That kind of rolls off the tongue.

These were random passwords generated by our computer. What we found in this study, surprisingly, was that the passphrases weren't that good. People weren't that much better at remembering passphrases than these random passwords, and because passphrases are longer, they take longer, and people make more mistakes when they type them. So it's not a clear win for passphrases. Sorry to all the xkcd fans. On the other hand, we found that the spoken passwords worked surprisingly well, and we're doing further research to see if we can make this approach better. One of the problems with some of the studies that we've done is because they're all done with Mechanical Turk, they're not real world passwords. They're passwords that they generated or the computer generated for them for our study. We wanted to know if people would behave the same way with their real passwords. So we talked to the IT security office at Carnegie Mellon and asked them if we could have everyone's real passwords. We weren't surprised when they were a little reluctant to share them with us, but we managed to work out a system with them where they would put all the real passwords for 25,000 students, faculty, and staff at the university on a locked computer in a locked room, with no Internet access, and they ran code that we wrote to analyze those passwords. They checked our code. They ran the code. And so we never saw anyone's password. We got some interesting results, and you Tepper students back there will be very interested in this. We found that passwords created by people who were affiliated with the computer science school were 1.8 times stronger than people who were affiliated with the business school. We have a lot of other really interesting demographic information. The other interesting thing we found was that when we compared the Carnegie Mellon passwords to the ones created on Mechanical Turk, there were a lot of similarities, and it helped validate our research methodology and show that collecting passwords using these Mechanical Turk studies is a valid way to study passwords. So that was good news. I want to close by talking about a few things that I learned while I was on sabbatical last year at the art school at Carnegie Mellon.

One of the things I did is some quilts, and I made this quilt. It's called "Security Blanket." (Laughter) And this quilt has 1,000 of the most common stolen passwords from the website RockYou. The size of the passwords is proportional to how often they appear in the stolen dataset. I created this word cloud, and I went through all of these 1,000 words and categorized them into some thematic categories. And sometimes, it was kind of hard to figure out which category they should go into, and then I color-coded them. Here are some examples of the difficulty. So, "Justin." Is it the username, their friend's name, their son's name? Maybe they're a Justin Bieber fan. Or "princess." Is it a nickname? Do they love Disney princesses? Or maybe it's the name of their cat. "iloveyou" appears many times in many different languages. There's a lot of love in these passwords. If you look closely, you'll see that there are also some swear words, but it was really interesting to see that there's a lot more love than hate in these passwords. And there are animals, lots of animals, and "monkey" is the most common animal and the 14th most common password overall. I found it really strange, and I wondered, "Why are monkeys so popular?" In our last password study, every time we found someone who made a password with the word "monkey" in it, we asked them why they had a monkey in their password. And what we found -- we found 17 people so far, I think, with the word "monkey" -- we found that about a third of them said they have a pet named "monkey" or a friend nicknamed "monkey," and about a third said they just like monkeys and they're really cute. And this one is really cute. It turns out that when we make passwords, we either make something that's really easy to type, a common pattern or something that reminds us of the word password or the account that we created the password for or whatever. Or we think about the things that make us happy, and we create our password based on the things that make us happy. And while that makes typing and remembering your password more fun, it also makes it a lot easier for them to guess your password.
I know a lot of these TED talks are inspiring and make you think about beautiful, happy things, but when you're creating your password, try to think about something else. Thank you. (Applause)

Watch the TED video. The translation into Greek has been done by Chryssa Rapessi and edited by Nikolao Benia

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS