munotes®

Password Selection and Management

Get access to whole semester resourcesSemester Pass

Chapter Eighty-Four

Syllabus topic Module 2, "Intrusion Techniques"

Pages 564 to 570 of 678

In one line

A good password is one an attacker's list does not contain: long, not a known or predictable choice, and never reused; the four ways a system helps people choose one are education, generated passwords, checking afterwards, and checking at the moment of choice.

In the words an answer should use: the goal of password selection is to eliminate guessable passwords while allowing users to choose passwords they can remember. Four basic techniques are used: user education, telling users why hard-to-guess passwords matter and how to choose them; computer-generated passwords, chosen at random by the system; reactive password checking, in which the system periodically runs its own password cracker to find guessable passwords and cancels them; and proactive password checking, in which the system checks each password when the user chooses it and refuses a weak one.

Why people choose badly

Morris and Thompson found in 1979 that when users chose freely, 86 per cent of 3,289 passwords fell into a few easily searched classes. Nothing has improved it since: people remember what is familiar, and what is familiar is guessable. Keystroke loggers and fake login pages defeat any password, long or short; NIST notes that such attacks "are equally effective on lengthy and complex passwords as they are on simple ones". Choosing well protects against guessing, which is the attack this chapter is about.

The four strategies

1. User education. Explain the risk and how to choose well. It is cheap and necessary, and NIST's guidance requires it: verifiers "SHALL offer guidance to the subscriber to help the subscriber choose a strong password". On its own it fails, because many users ignore it or cannot judge what is guessable.

2. Computer-generated passwords. The system picks the password at random, so nothing about the user makes it guessable. Random strings are hard to remember and so get written down, and the generator itself must be good. Morris and Thompson tell of an installation whose system-chosen passwords were 8 characters from 36, which would have taken 112 years to search, but which came from a generator with only 2^15 starting values: an attacker tried them all "using a total of only about one minute of machine time". Today the useful form is a password manager that generates and remembers long random passwords, which NIST says verifiers "SHALL allow".

3. Reactive password checking. The system runs its own password cracker against its own password file from time to time, and cancels or flags any password it finds. It catches weak passwords, but only after they have been in use, possibly for a long time; the cracking takes much computing; and anyone who can run the checker needs the password hashes.

munotes.in564

Password Selection and Management

4. Proactive password checking. The system checks each password at the moment the user chooses it, and refuses a weak one. This is the approach that has lasted. Its forms have been simple rules, comparison with a dictionary of bad passwords, and, to hold a large dictionary in a small space, a Bloom filter, as in Eugene Spafford's OPUS system at Purdue. Today's form is NIST's blocklist: verifiers "SHALL compare the prospective secret against a blocklist that contains known commonly used, expected, or compromised passwords", and "The entire password SHALL be subject to comparison, not substrings or words that might be contained therein."

The run: the arithmetic, a Bloom filter, and two rulebooks

The listing works out how large the search is for passwords chosen at random, reproduces the Morris and Thompson generator story in numbers, sizes and builds a Bloom filter as Spafford did, and applies an old-style composition rule and NIST's current rule to the same four passwords.

# Choosing passwords: the arithmetic of guessing, a proactive checker built as a Bloom filter
# (Spafford's OPUS), and the old composition rule set beside NIST's current one.
import hashlib, math, random

# ---- 1. how many guesses a RANDOMLY chosen password needs -----------------------------------
print('1. RANDOM PASSWORDS: the size of the space an attacker must search')
for label, space in [('8 lower-case letters', 26 ** 8),
                     ('8 of letters and digits', 62 ** 8),
                     ('8 of all 94 printable characters', 94 ** 8),
                     ('15 lower-case letters', 26 ** 15),
                     ('4 words from a 7,776-word list', 7776 ** 4),
                     ('6 words from a 7,776-word list', 7776 ** 6)]:
    print('   %-34s %5.1f bits   about 10^%d guesses' % (label, math.log2(space),
                                                         len(str(space)) - 1))
print('   one word from 7,776 is worth %.1f bits' % math.log2(7776))

# ---- 2. Morris and Thompson's machine-chosen passwords: 36^8 on paper, 2^15 in fact ----------
print()
print('2. A GENERATOR IS ONLY AS STRONG AS ITS SEED')
print('   8 characters from 36: %s passwords, %.1f bits'
      % (format(36 ** 8, ','), math.log2(36 ** 8)))
print('   a generator with 2^15 starting values: %s passwords, 15.0 bits' % format(2 ** 15, ','))
print('   the attacker\'s work cut by a factor of %s' % format(36 ** 8 // 2 ** 15, ','))

# ---- 3. a proactive checker: OPUS's Bloom filter ---------------------------------------------
def bits_needed(n, d, p):
    """Spafford's formulas: unset share phi = (1 - d/N)^n, false positives P = (1 - phi)^d."""
    phi = 1 - p ** (1 / d)
    return d / (1 - phi ** (1 / n)), phi

print()
print('3. OPUS SIZED AS SPAFFORD SIZED IT (250,000 words, 6 hash functions)')
for p in (0.005, 0.01):
    size, phi = bits_needed(250_000, 6, p)
    print('   false positives %.1f%%: %s bits, %s bytes, unset share %.3f'
          % (p * 100, format(round(size), ','), format(round(size / 8), ','), phi))

BASE = ['password', 'sunshine', 'cricket', 'mumbai', 'india', 'welcome', 'dragon', 'monkey',
        'qwerty', 'iloveyou', 'princess', 'football', 'shadow', 'master', 'superman', 'krishna']
TAILS = ['', '1', '12', '123', '1234', '!', '1!', '@123', '#1', '007',
         '2024', '2025', '2026', '@2026', '99', '786']
forbidden = {case(word) + tail for word in BASE for tail in TAILS
             for case in (str.lower, str.capitalize, str.upper)}
n, d = len(forbidden), 7
N = round(-n * d / math.log(1 - 0.01 ** (1 / d)))    # sized for 1% false positives
bloom = bytearray((N + 7) // 8)

def spots(word):
    for i in range(d):
        h = hashlib.sha256(bytes([i]) + word.encode()).digest()
        yield int.from_bytes(h[:8], 'big') % N

for word in forbidden:
    for s in spots(word):
        bloom[s // 8] |= 1 << (s % 8)

def rejected(word):
    return all(bloom[s // 8] >> (s % 8) & 1 for s in spots(word))

rng = random.Random(1992)
alphabet = 'abcdefghijklmnopqrstuvwxyz0123456789'
trials, wrong = 100_000, 0
for _ in range(trials):
    w = ''.join(rng.choice(alphabet) for _ in range(10))
    wrong += w not in forbidden and rejected(w)
print('   a filter of %s forbidden passwords in %s bits (%s bytes), %d hash functions'
      % (format(n, ','), format(N, ','), format(len(bloom), ','), d))
print('   every forbidden password rejected:', all(rejected(w) for w in forbidden))
print('   harmless strings wrongly rejected: %d of %s, %.2f%%'
      % (wrong, format(trials, ','), 100 * wrong / trials))

# ---- 4. the old composition rule against NIST SP 800-63B-4 ------------------------------------
def old_rule(pw):
    return (len(pw) >= 8 and any(c.isupper() for c in pw) and any(c.islower() for c in pw)
            and any(c.isdigit() for c in pw) and any(not c.isalnum() for c in pw))

def nist_rule(pw):           # single-factor: 15 characters at least, and not on the blocklist
    return len(pw) >= 15 and not rejected(pw)

print()
print('4. %-28s %-18s %s' % ('PASSWORD', 'OLD RULE', 'SP 800-63B-4'))
for pw in ['Password1!', 'Sunshine@2026', 'Tq9$wd3@Lp0z', 'teal kettle monsoon ledger']:
    print('   %-28s %-18s %s' % (pw, 'accepted' if old_rule(pw) else 'refused',
                                  'accepted' if nist_rule(pw) else 'refused'))
munotes.in565

Password Selection and Management

1. RANDOM PASSWORDS: the size of the space an attacker must search
   8 lower-case letters                37.6 bits   about 10^11 guesses
   8 of letters and digits             47.6 bits   about 10^14 guesses
   8 of all 94 printable characters    52.4 bits   about 10^15 guesses
   15 lower-case letters               70.5 bits   about 10^21 guesses
   4 words from a 7,776-word list      51.7 bits   about 10^15 guesses
   6 words from a 7,776-word list      77.5 bits   about 10^23 guesses
   one word from 7,776 is worth 12.9 bits

2. A GENERATOR IS ONLY AS STRONG AS ITS SEED
   8 characters from 36: 2,821,109,907,456 passwords, 41.4 bits
   a generator with 2^15 starting values: 32,768 passwords, 15.0 bits
   the attacker's work cut by a factor of 86,093,442

3. OPUS SIZED AS SPAFFORD SIZED IT (250,000 words, 6 hash functions)
   false positives 0.5%: 2,811,022 bits, 351,378 bytes, unset share 0.586
   false positives 1.0%: 2,404,167 bits, 300,521 bytes, unset share 0.536
   a filter of 768 forbidden passwords in 7,367 bits (921 bytes), 7 hash functions
   every forbidden password rejected: True
   harmless strings wrongly rejected: 1071 of 100,000, 1.07%

4. PASSWORD                     OLD RULE           SP 800-63B-4
   Password1!                   accepted           refused
   Sunshine@2026                accepted           refused
   Tq9$wd3@Lp0z                 accepted           refused
   teal kettle monsoon ledger   refused            accepted
munotes.in566

Password Selection and Management

What the run establishes, in order.

Length does more than variety. Eight random characters from all 94 printable characters give 52.4 bits; fifteen random lower-case letters give 70.5. Six words picked at random from a 7,776-word list give 77.5 bits, which EFF's 2016 word list describes as "about 12.9 bits" a word. These figures hold only for random choices. A password a person thinks up has far less strength than its length suggests, which is why NIST now judges passwords "based primarily on password length" and a blocklist, rather than an entropy estimate.

A generator is only as strong as its seed. The 36^8 passwords of Morris and Thompson's installation looked like 41.4 bits; the generator could produce only 32,768 of them, 15 bits, and cut the attacker's work by a factor of 86 million.

A Bloom filter holds a large list in a small space, and never lets a listed password through. Spafford's formulas give, for 250,000 words and six hash functions, 2,811,022 bits, 351,378 bytes at a 0.5 per cent false-positive rate, and 300,521 bytes at 1 per cent: his report printed "2,800,000 bits", "350K bytes" and "300K bytes". The filter built here holds 768 forbidden passwords in 921 bytes and rejects every one of them. Its only error is the other way: about 1 in 100 harmless strings is wrongly refused, 1.07 per cent against the 1 per cent it was designed for, and the user simply picks another.

Composition rules reward the wrong passwords. "Password1!" and "Sunshine@2026" satisfy the old rule of upper case, lower case, digit and symbol, and are exactly what attackers try first; NIST's appendix uses "Password1!" as its own example. A random 12-character string also passes the old rule but is too short for NIST's single-factor minimum of 15. A four-word phrase of lower-case words fails the old rule and passes NIST's.

What current guidance says

NIST SP 800-63B-4 (July 2025) reverses several rules that most notes still teach:

RuleWhat many notes teachNIST SP 800-63B-4
Minimum length8 characters15 when the password is the only factor; 8 when part of multi-factor authentication
Maximum lengthoften 16 or lessshould permit at least 64
Compositionrequire upper case, digits and symbols"SHALL NOT impose other composition rules"
Periodic changeevery 30, 60 or 90 days"SHALL NOT require subscribers to change passwords periodically", but SHALL force a change on evidence of compromise
Blocklistrarely mentionedSHALL check against common, expected and compromised passwords
Hints and security questionscommonSHALL NOT
Password managers and pastesometimes blockedSHALL allow managers and autofill; SHOULD allow paste
Failed attemptsvariesSHALL rate-limit
munotes.in567

Password Selection and Management

Why forced expiry was dropped. NIST's own FAQ explains that users forced to change passwords "often select a secret that is similar to their old memorized secret by applying a set of common transformations such as increasing a number in the password", "Sunshine@2025" becoming "Sunshine@2026", and attackers apply the same transformations. Forcing a change when there is evidence of compromise protects; forcing it by the calendar mostly produces patterns.

Management, as well as selection

  • Never reuse a password across sites: a breach of one then opens all the others. A password manager makes unique passwords practical.
  • Change a password when it may have been exposed, not by the calendar.
  • Use a second factor where it is offered; a stolen password alone then does not open the account.
  • Never share a password, even with a friend or classmate; using it would be using another person's password, which is what section 66C of the IT Act punishes.

Distinctions that carry marks

Reactive checkingProactive checking
Whenperiodically, after passwords are setat the moment of choosing
Howthe system cracks its own filethe new password is compared with a list or rules
Weak passwords existuntil the next checknever
Costheavy computing, repeatedone check per change
Composition ruleBlocklist
Refusespasswords lacking certain character typesknown, common or breached passwords
Accepts "Password1!"yesno
NIST SP 800-63B-4forbiddenrequired

What beginners get wrong here

Equating complexity with strength. Symbols and capitals in predictable places add little; attackers' lists already contain "Password1!". Length and not being on a list matter more.

Calculating a person's password strength as if it were random. 94^8 describes a random string, not one a person made up; a human choice of 8 characters is usually far weaker.

Recommending a change every 90 days. Current NIST guidance forbids periodic forced changes and requires a change only when there is evidence of compromise.

Thinking a Bloom filter may let a weak password through. It never misses a listed password; its only error is occasionally refusing a good one.

Quick revision

  • Four strategies: user education, computer-generated passwords, reactive checking (crack your own file), proactive checking (check at the moment of choice).
  • Generated passwords are only as strong as the generator: Morris and Thompson's 36^8 was really 2^15.
  • Bloom filter (Spafford's OPUS): d hash functions set bits; a word is refused if all its bits are set; no false negatives, a small rate of false positives. 250,000 words, 6 hashes, 0.5% needs about 350 KB.
  • Random passwords: 8 of 94 is 52.4 bits; 6 words of 7,776 is 77.5 bits. Human choices are far weaker.
  • SP 800-63B-4: at least 15 characters single-factor (8 with MFA), allow 64, no composition rules, no periodic changes, blocklist, no hints or security questions, allow password managers, rate-limit attempts.
munotes.in568

Password Selection and Management

Test yourself

1. Describe the four basic techniques of password selection. User education tells users why guessable passwords are dangerous and how to choose good ones, but depends on users following it. Computer-generated passwords are chosen at random by the system, which removes guessable patterns but makes them hard to remember and depends on a good random generator. Reactive password checking has the system periodically run a password cracker on its own file and cancel any password it finds, but weak passwords stay in use until the next run and the checking is costly. Proactive password checking tests each password when the user chooses it and refuses weak ones, using rules, a dictionary of bad passwords or a compact structure such as a Bloom filter.

2. How does a Bloom filter serve as a proactive password checker? The filter is an array of N bits, all zero at first, and d independent hash functions each map a word to a position in the array. Every word in the dictionary of bad passwords is hashed by all d functions and the d positions are set to 1. When a user proposes a password, it is hashed the same way; if all d positions are 1 it is refused as probably in the dictionary, and if any is 0 it is certainly not in the dictionary and is accepted. A listed password is never accepted; a small, controllable fraction of good passwords is wrongly refused, and the filter is far smaller than the dictionary itself.

3. Why does current NIST guidance forbid composition rules and periodic password changes? Because users respond to composition rules in predictable ways, turning "password" into "Password1!", which attackers try first, while the rules make passwords harder to remember and more likely to be written down. Periodic forced changes produce predictable variations of the old password. NIST SP 800-63B-4 therefore requires a minimum length, a check against a blocklist of common and compromised passwords, and a forced change only when there is evidence of compromise.

4. Compare the strength of an eight-character random password with a six-word random passphrase. Eight characters chosen at random from the 94 printable characters give 94^8 possibilities, about 52.4 bits. Six words chosen at random from a list of 7,776 give 7,776^6 possibilities, about 77.5 bits, some 25 bits or about 36 million times more, and are easier to remember. Both figures apply only if the choice is truly random.

munotes.in569

Password Selection and Management

5. What rules for passwords does NIST SP 800-63B-4 lay down? Passwords used as the only factor must be at least 15 characters, and at least 8 when part of multi-factor authentication; at least 64 characters should be allowed, with all printing characters, spaces and Unicode. No other composition rules may be imposed and periodic changes may not be required, but a change must be forced on evidence of compromise. Every new password must be checked in full against a blocklist of common, expected and compromised passwords; hints and security questions are not allowed; password managers and autofill must be allowed; and failed attempts must be rate-limited.

munotes.in570

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.

Issue
Done!