We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Best way to make an uncrackable passphrase, using What3words

1234568»

Comments

  • noitsnotme
    noitsnotme Posts: 1,594 Forumite
    Fifth Anniversary 1,000 Posts Name Dropper
    edited 28 January at 9:20PM

    It took you nearly 2 years to reply to bob2302s post! Let’s hope you find your passwords a bit quicker than that.

  • sausage_time
    sausage_time Posts: 1,914 Senior Ambassador
    Tenth Anniversary 1,000 Posts Name Dropper Photogenic

    Three words: UsePasswordManager

    I’m a Forum Ambassador and I support the Forum Team on the Credit CardsSavings & investments, and Budgeting & Bank Accounts boards. If you need any help on these boards, do let me know. Please note that Ambassadors are not moderators. Any posts you spot in breach of the Forum Rules should be reported via the report button, or by emailing forumteam@moneysavingexpert.com.
    All views are my own and not the official line of MoneySavingExpert.
  • Barand
    Barand Posts: 2 Newbie
    Fifth Anniversary First Post

    OP is focussing too much on having an "uncrackable" password when the password itself is only part of the solution and vulnerable on its own without an additional layer of protection like Multi Factor Authentication through a OTP or hardware key. As mentioned several times above a good Password Manager will help you generate strong and unique passwords using fit for purpose algorithms and don't rely on you memorising them. Keeping your password safe is far more important than the theoretical time to crack it as most hacks will result from stolen / leaked credentials from data breaches or by being tricked into giving them over from social engineer or phishing attempts.

  • spud17
    spud17 Posts: 4,452 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker

    I've got other things to worry about rather than if a password is crackable in 100billion years or 101billion years.

    Move along, nothing to see.
  • booneruk
    booneruk Posts: 886 Forumite
    Seventh Anniversary 500 Posts Name Dropper
    edited 31 January at 7:58PM

    Well, the 'crackable' risk and computational effort will only (generally) apply if a bad actor hacks an institution you use and extracts your hashed password - after which they can then get to work on brute forcing it. It's this brute force that can take thousands of years with modern hash algorithms and computing power - however, the brute force could always luck it and get the password correct instantly. Thankfully there are further methods known as salt and peppering which massively increase brute force complexity (and that is too technical to go into in a brief post)

    Some organisations used to store passwords in plain text - thank god those days are largely gone. Any organisation that can email you your password is highly likely still committing this crime!

    If anyone thinks a brute force attack could be conducted against a bank's login page they're mistaken. 3 or so failed login attempts and you're into account locked territory.

    Anyway, back to the OP's 'revelation'. I wouldn't use a password constructed out of multiple dictionary words - that's keeping things too simple.

  • Vitor
    Vitor Posts: 1,382 Forumite
    1,000 Posts Second Anniversary Photogenic Name Dropper
    edited 31 January at 8:08PM

    Mostly agree on the attack model: offline cracking after a breach is the real risk, not hammering login pages. Salting and slow hashes matter.

    Where I disagree is the dismissal of multi-word passphrases. The weakness isn’t “dictionary words”, it’s short or predictable ones. Several randomly chosen words give far more entropy than most symbol-stuffed passwords people invent. “It could guess it instantly” is technically true but irrelevant in practice. Length and unpredictability dominate with current compute.

    The search space only collapses if the attacker knows the construction method. If they don’t know you’re using what3words, they have to assume a general passphrase model and search an enormous mixed space. At that point, three uncommon words is just a long, high-entropy string.

  • booneruk
    booneruk Posts: 886 Forumite
    Seventh Anniversary 500 Posts Name Dropper
    edited 31 January at 8:13PM

    Well, what I mean is - throw a couple of symbols into the mix, it's not hard 😁

  • outtatune
    outtatune Posts: 877 Forumite
    Fourth Anniversary 500 Posts Name Dropper
    security.png

    Source: https://xkcd.com/538/

  • Frozen_up_north
    Frozen_up_north Posts: 3,130 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic

    A user name and password are not secure against malware stealing your browser password file and other risks.

    As several mentioned, an additional factor such as an authenticator app, or being sent an email with a few numbers, increases security significantly.

    Windows helps you remember passwords too, it will respond by telling you what your password is: "your password is incorrect", change it to incorrect1 and continue 🤣.

Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 354.4K Banking & Borrowing
  • 254.4K Reduce Debt & Boost Income
  • 455.4K Spending & Discounts
  • 247.3K Work, Benefits & Business
  • 604K Mortgages, Homes & Bills
  • 178.4K Life & Family
  • 261.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.