When you have followed the well advice that you should create long passwords containing numbers,letters and other symbols in order to keep your online banking accounts protected as well as keepingyour data secure, you may be in for an unpleasant surprise.
A research built on five years of extensive research by team led by three notable professors from Carnegie Mellon University and which was presented at the Human Computer Interaction conference in Korea, shows how long, seemingly complex passwords can often be far more easily cracked at a shorter time than most would tend to believe.
The core problems stem from human weaknesses (and like most password vulnerabilities) and relative predictability of human behavior – as a result of our limited human minds, most users often create passwords in ways that make them far weaker than mathematics would suggest.
One key finding that the Carnegie Mellon University team confirmed (through research on groups of people asked to create passwords, with technical requirements and then only to be recalled a few days later) was that when people must include both letters and a minimum of one number, the passwords are typically with all characters but one being letters and place the number at the end. This typical format and the regularity of such a password generation scheme dramatically lowers the number of possibilities that hacking engines would need to guess in order to crack a password with brute force.While it is certain that not all passwords follow such a model, a criminal utilizing a software engine that leverages on the knowledge of the said human predictability is likely to successfully crack accounts faster than others that who does not.
Other serious vulnerabilities were also discovered via semantic analysis. By reviewing a large corpus of English language data the team used the content of Wikipedia, song lyrics, a baby and pet names dictionary, Google’s bigrams and trigrams among others – educated predictions can be made on certain characters’ sequences within a password or passphrase. A passphrase that begins “mybonnielies” is going to continue “over the ocean” far more often that raw mathematical probability would suggest.
Leveraging knowledge of the mentioned weaknesses and many others described, the Carnegie Mellon team created a password guessing engine, and a system for rating passwords based on how difficult they are to guess. Not surprisingly, many longer passwords are far easier to guess than shorter ones.
Portfolio
Packages
Careers

Comments 0