<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>VentureBeat &#187; passphrases</title>
	<atom:link href="http://venturebeat.com/tag/passphrases/feed/" rel="self" type="application/rss+xml" />
	<link>http://venturebeat.com</link>
	<description>News About Tech, Money and Innovation</description>
	<lastBuildDate>Wed, 22 May 2013 05:33:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='venturebeat.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/c6d8c27ffa1c5a7f106f97e434437baf?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>VentureBeat &#187; passphrases</title>
		<link>http://venturebeat.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://venturebeat.com/osd.xml" title="VentureBeat" />
	<atom:link rel='hub' href='http://venturebeat.com/?pushpress=hub'/>
<copyright>Copyright 2013, VentureBeat</copyright>		<item>
		<title>Stop using proper grammar, its making your passwords weak</title>
		<link>http://venturebeat.com/2013/01/24/password-grammar/</link>
		<comments>http://venturebeat.com/2013/01/24/password-grammar/#comments</comments>
		<pubDate>Fri, 25 Jan 2013 01:55:16 +0000</pubDate>
		<dc:creator>Meghan Kelly</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[grammar]]></category>
		<category><![CDATA[passphrases]]></category>
		<category><![CDATA[password crackers]]></category>
		<category><![CDATA[passwords]]></category>

		<guid isPermaLink="false">http://venturebeat.com/?p=610328</guid>
		<description><![CDATA[<p>When it comes to passphrases, using proper grammar could actually hurt your password, rather than help you remember&#160;it.</p>
<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=610328&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><a href="http://venturebeat.files.wordpress.com/2013/01/password-login.jpg" target="_blank"><img class="aligncenter size-full wp-image-610334" alt="password login" src="http://venturebeat.files.wordpress.com/2013/01/password-login.jpg?w=655&#038;h=502" width="655" height="502" /></a></p>
<p>You&#8217;ve had grammar drilled into your head since elementary school, but when it comes to creating passwords, researchers are now saying to forget everything you&#8217;ve learned.</p>
<p>Institute of Software Research Ph.D student <a href="http://www.eurekalert.org/pub_releases/2013-01/cmu-gus012413.php" target="_blank" target="_blank">Ashwini Rao and her team discovered that using proper grammar</a> in your password actually weakens their security. That is, grammar is easier to predict and leads us to use pronouns, adverbs, and adjectives, which are easier for password crackers to solve. Rao&#8217;s team ran a homemade password cracker &#8212; or a piece of software that attempts to guess your password &#8212; that was outfitted with grammar knowledge. According to a statement released by Rao&#8217;s team, the cracker beat out &#8220;state-of-the-art password crackers,&#8221; solving 10 percent of the 1,434 passwords they fed it.</p>
<p>Passphrases are the in vogue password of choice nowadays, which may lead people to start using sentences as their &#8220;phrases.&#8221; For instance, you might use &#8220;iambetterthansheis.&#8221; Rao says that pronouns are significantly easier to crack than nouns simply because there are far fewer of them. &#8220;Meghanpuzzleasstown&#8221; is likely to be much more difficult to crack.</p>
<p>&#8220;I&#8217;ve seen password policies that say, &#8216;Use five words,&#8217;&#8221; Rao said in a statement. &#8220;Well, if four of those words are pronouns, they don&#8217;t add much security.&#8221;</p>
<p>Stick with passphrases that are three or four words, that are completely random. Look around the room and start picking out words. But mindful not to pick words that go together. Researchers have already determined that <a href="http://venturebeat.com/2012/03/14/passphrases-weak/" target="_blank">passphrases might be weaker than expected</a>, just because humans tend to put words together that, well, make sense. That is, you might think baseballdiamondhorse. Sure, a horse doesn&#8217;t have much to do with baseball or diamonds, but a baseball diamond is a thing that could easily be associated.</p>
<p>Rao will present further findings at the Association for Computing Machinery&#8217;s Conference on Feb. 20.</p>
<p><em><a href="http://www.shutterstock.com/pic-106271726/stock-photo-laptop-computer-with-login-web-screen.html" target="_blank" target="_blank">Password image</a> via <a href="http://www.shutterstock.com/" target="_blank" target="_blank">Shutterstock</a></em></p>
<br />Filed under: <a href='http://venturebeat.com/category/security/'>Security</a>  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=610328&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://venturebeat.com/2013/01/24/password-grammar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<enclosure url="http://venturebeat.files.wordpress.com/2013/01/password-login.jpg?w=160" /><source url="http://venturebeat.com/2013/01/24/password-grammar/">Stop using proper grammar, its making your passwords weak</source>
		<media:content url="http://1.gravatar.com/avatar/a73335ff3a637d11555a46ba2b112ded?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">mkel31</media:title>
		</media:content>

		<media:content url="http://venturebeat.files.wordpress.com/2013/01/password-login.jpg" medium="image">
			<media:title type="html">password login</media:title>
		</media:content>
	</item>
		<item>
		<title>Passphrases weaker than expected due to lack of imagination</title>
		<link>http://venturebeat.com/2012/03/14/passphrases-weak/</link>
		<comments>http://venturebeat.com/2012/03/14/passphrases-weak/#comments</comments>
		<pubDate>Thu, 15 Mar 2012 01:29:10 +0000</pubDate>
		<dc:creator>Meghan Kelly</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[logins]]></category>
		<category><![CDATA[passphrases]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[PayPhrase]]></category>

		<guid isPermaLink="false">http://venturebeat.com/?p=403568</guid>
		<description><![CDATA[</p>
<p>When passwords weren&#8217;t good enough, passphrases came into play as a much safer login option. But a new study is saying passphrases may not be as effective as you think.</p>
<p>Researchers Joseph Bonneau and Ekaterina Shutova looked at Amazon&#8217;s now&#160;&#8230;</p>
<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=403568&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><a href="http://venturebeat.com/2012/03/14/passphrases-weak/passphrase-2/" rel="attachment wp-att-403651"><img class="alignleft size-full wp-image-403651" title="Passphrase" src="http://venturebeat.files.wordpress.com/2012/03/passphrase.jpg?w=747&#038;h=426" alt="" width="747" height="426" /></a></p>
<p>When passwords weren&#8217;t good enough, passphrases came into play as a much safer login option. But a new study is saying passphrases may not be as effective as you think.</p>
<p>Researchers Joseph Bonneau and Ekaterina Shutova looked at Amazon&#8217;s now out of commission PayPhrase System to see the types and effectiveness of passphrases people chose. PayPhrase was a passphrase-based login system that allowed consumers to go through the e-commerce check out line quickly. It required users set up a phrase of two words or more that would be connected to a credit card and shipping address. Entering the passphrase and a PIN would result in the purchase. Because the phrase itself related to financial information, PayPhrase did not allow people to use the same phrase. This gave Bonneau and Shutova the ability to query PayPhrase and collect a wide range of passphrases chosen naturally by humans.</p>
<p>&#8220;Our results suggest that users aren’t able to choose phrases made of completely random words, but are influenced by the probability of a phrase occurring in natural language,&#8221; said Bonneau and Shutova <a href="http://www.cl.cam.ac.uk/~jcb82/doc/BS12-USEC-passphrase_linguistics.pdf"title="Linguistic properties of multi-word passphrases"  target="_blank" target="_blank">in their report</a>. &#8220;Examining the surprisingly weak distribution of phrases in natural language, we can conclude that even 4-word phrases probably provide less than 30 bits of security, which is insufficient against offline attack.</p>
<p>They attempted a dictionary attack against the formed database of passphrases. A dictionary attack is when a hacker takes a list of well-known words or phrases, chooses which ones are most likely to succeed, and then attempts all of them. Bonneau and Shutova formed their list by gathering various sports team names, movies titles, album titles, proper nouns, names and more using IMDB, Wikipedia, and a number of other popular websites. Using this list, they ran their own dictionary attack.</p>
<p>The experiment showed that people rarely chose random phrases such as &#8220;panda train sunset.&#8221; This makes the passphrase significantly more vulnerable to attack. People also tended to &#8220;prefer phrases which are either a single modified noun (&#8220;operation room&#8221;) or a single modified verb (&#8220;send immediately&#8221;), according to Bonneau in a <a href="http://www.lightbluetouchpaper.org/2012/03/07/some-evidence-on-multi-word-passphrases/"title="Bonneau blog post"  target="_blank" target="_blank">blog post about the study</a>.</p>
<p>The two do conclude that their test was limited to the 100,000 passphrases extracted from the PayPhrase system, and suggest the phrase in combination with a 4-digit PIN makes it significantly stronger. But for login tools that don&#8217;t require two forms of identification, a stronger, less natural passphrase is going to be necessary.</p>
<p>&#8220;We recommend further collaboration between the security and linguistics research communities to explore what is possible in multi-word passphrases,&#8221; the team stated, &#8220;In particular, user testing for longer phrases is necessary to determine the extent to which users will tend to choose passphrases with natural-language-like properties as more words are required and not resort to easier-to-remember patterns like repeated words, idioms, or well-known titles.&#8221;</p>
<p><em>via <a href="http://www.readwriteweb.com/enterprise/2012/03/passphrases-maybe-not-as-secur.php"title="ReadWriteWeb"  target="_blank" target="_blank">ReadWriteWeb</a>; <a href="http://www.shutterstock.com/pic-60891964/stock-photo-computer-security-concept-shot-with-binary-code-and-password-text-great-for-technology-online.html"title="Image"  target="_blank" target="_blank">Image</a> via <a href="http://www.shutterstock.com/"title="Shutterstock"  target="_blank" target="_blank">Shutterstock</a></em></p>
<br />Filed under: <a href='http://venturebeat.com/category/security/'>Security</a>  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=403568&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://venturebeat.com/2012/03/14/passphrases-weak/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<enclosure url="http://venturebeat.files.wordpress.com/2012/03/passphrase.jpg?w=160" /><source url="http://venturebeat.com/2012/03/14/passphrases-weak/">Passphrases weaker than expected due to lack of imagination</source>
		<media:thumbnail url="http://venturebeat.files.wordpress.com/2012/03/passphrase.jpg?w=160" />
		<media:content url="http://venturebeat.files.wordpress.com/2012/03/passphrase.jpg?w=160" medium="image">
			<media:title type="html">Passphrase</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/a73335ff3a637d11555a46ba2b112ded?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">mkel31</media:title>
		</media:content>

		<media:content url="http://venturebeat.files.wordpress.com/2012/03/passphrase.jpg" medium="image">
			<media:title type="html">Passphrase</media:title>
		</media:content>
	</item>
	</channel>
</rss>
