Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Why Passwords Sucks and What Can You Do About It

Why Passwords Sucks and What Can You Do About It

This is a "primer" talk I did for students from Tec de Monterrey about Password Security Awareness a few years ago.

Eduardo Urias

July 27, 2018
Tweet

More Decks by Eduardo Urias

Other Decks in Technology

Transcript

  1. A N D W H AT Y O U C

    A N D O A B O U T I T W H Y PA S S W O R D S S U C K S
  2. PA S S W O R D S Universal means

    of getting 
 ACCESS to ANYTHING
  3. S E V E R A L A C C

    O U N T S L AT E R …
  4. A L L I S G O O D U

    N T I L …
  5. L E T ’ S T RY A G A

    I N R E L A X
  6. W H AT I F I H AV E O

    N E PA S S W O R D T H AT I S L I K E R E A L LY S T R O N G , Y O U K N O W ?
  7. W H AT I F I H AV E O

    N E PA S S W O R D T H AT I S L I K E R E A L LY S T R O N G , Y O U K N O W ?
  8. T H E R E A L P R O

    B L E M Password Reuse
  9. PA S S W O R D C R A

    C K I N G • The ability to crack passwords using computer programs is also a function of the number of possible passwords per second which can be checked. • For some password hash, desktop computer can test over a hundred million passwords per second or billions per second if a GPU-based cracking tool is used. • The rate of guessing heavily depends on the hashing function used and how strong the password is.
  10. • A user selected 8 character password with numbers, mixed

    case and symbols with commonly selected password filtered out can be cracked in seconds if the hashing function is naive. • Some commercial products claim the ability to test almost 3 billion passwords per second on a desktop computer using a high-end graphics processor. Cracking a 10 letter single-case password in one day.
  11. E A S Y T O R E M E

    M B E R , H A R D T O G U E S S • A password that is easy to remember is generally easy for an attacker to guess • A password that is difficult to remember reduce the security of a system since they are more likely to be written out, frequently reset or reused. Strict requirements on password creation usually cause this effect as well.
  12. C L E A R LY, T H I S

    I S N O T W O R K I N G .
  13. – S I G M U N N . P

    O R T E R ( S O R TA ) “What about a Passphrase?”
  14. A Passphrase is similar to a password in usage, but

    is generally longer for added security.
  15. Passwords Passphrases 12345 qwerty un4uth0r1z3d $s0m3P4ssw0rd$ The quick brown fox

    jumps over the lazy dog Now is the time for all good men to come to the aid of their country If you want to test a man's character give him power
  16. T W O FA C T O R A U

    T H E N T I C AT I O N 2 FA