Easier to remember secure passwords

Is it true that adding a symbol after each letter to a long word used as a password makes it very resistant to dictionary and brute force attack?

ie: "forbearance" vs "f/o/r/b/e/a/r/a/n/c/e"

Because that's way easier to remember than "1@f#r$l_5&G-b+8(9)oO/".

Other urls found in this thread:

passwordcard.org/en
eff.org/dice
world.std.com/~reinhold/diceware.html
rempe.us/diceware/#eff
passwordcreator.org/diceware.html
rumkin.com/tools/password/diceware.php
twitter.com/NSFWRedditImage

It would probably help to alternate different symbols. But length is the most important thing. Which that password seems to accomplish

Cool. I guess studying all those SAT words is finally gonna pay off.

This.
Anything to lengthen a password or increase the potential characters used in it is a good thing.
Using quick tricks that are easy to remember are a help, but if people know the tricks you use, then they can write more efficient algorithms to guess your password quicker.

The only thing that matters for a brute force attack is the length.

Just write a simple script that hashes the website or service name with a master password. Then you only need to remember one password for everything.

Won't their dictionary attack become insanely inefficient if they do that? Now they have to try every symbol in front of each letter from thousands of possible words.

I'm mostly reffering to personal encryption like 7zips and website passwords for yourself.

Make up your own schema for passwords. Here's my old one for an idea

{Sitenamebackwards}{delimiter}{randomword}{symbol}{number}{delimiter#2}{randomword-different language}{delimiter}

So a password for Sup Forums

NachFour+osprey~822?verde+

Get creative and make it easy to remember

That seems significantly harder to remember.

It all depends on the certainty they have that you used a specific method to derive a password.

For example, the "CorrectBatteryHorseStaple" password method by xkcd, If everyone used that it would have an effective entropy of only ^4 not the 2^44 like the comic suggests because youd rule out all the astounding passwords of that length which werent made of english words.

This guy is on the mark, invent your own little scheme for making rememberable password, it doesnt have to be that hard but any random method you can remember to derive a password is as safe as a random password provided people dont know how you derive it.

No, well I have a strategy for remembering them .


Try the head-tail pattern

{Symbols}{sitenamebackwards}{number}{Symbols}

@>>koobeecaf9256

though this does give me an idea..

spanish+english word with an alternating symbol after each letter

"s?e+r?c+a?a+c?c+e?d+e?"

whatever works man.

Cool, glad I made this thread. Hopefully it helped a few anons here make better passwords.

Problem with these complicated passwords with symbols is that they're more difficult to type fluently, whereas lengthy word-based ones can be entered quickly without errors.

I write down my passwords, seems simpler than coming up with a password scheme and remembering it.

Not really a problem if you can touch type.

OPSEC > Convenience

It'll be all nice and quick and dandy until your nudes get leaked on Sup Forums

You can use things like password tables if you write things down -passwordcard.org/en

cool idea, but I'd be fucked on my phone.

I'm saying I'd rather be typing a 60 characters password comprised entirely of words than a 15 characters password filled with symbols and numbers. I don't have the knowledge or the time to come up with convoluted schemes for creating "shorter" passwords that are MIGHT be secure than long ones, so I'm going for length.

use diceware.

use keepassxc generator

...

i already forget the most simple paswords as it is lol

For what purpose? You're already way out of any password list with four words and a character.

you have never heard of dice password? it is uncrackable until quantum computer become available for the mass

what is dice?
eff.org/dice
world.std.com/~reinhold/diceware.html

I am lazy and don't want buy dice:
rempe.us/diceware/#eff (this site will calculate the entriphy of your pass too)

passwordcreator.org/diceware.html
similar to the one above, i often use overkill

rumkin.com/tools/password/diceware.php
(the best one, it will not use predefined psudo randamness, it will generate one from your mouse's movement)

hope this helps.

user

why do you need big and hard to remember password?
just don't let other people use your machine and you will be fine