Breaking the Password Security Standards Using Offline Attacks and Public User Attributes
Haggai Rei G. Cacacho, Harbie Jay L. Manuel, Evelio L. Failoga, James Patrick A. Acang · 2019
Password security standards based on the Shannon Entropy were made to ensure that users are protected from attacks. This research investigates the possibility of breaking the password security standards using offline attacks and public user attributes. The idea here is to reduce the keyspace by collecting a character set that is likely to be chosen as a password. Ten million compromised passwords were used to establish the Dictionary Character Set, while 1.4 billion compromised email accounts were used to establish the User-Attribute Character Set. Based on the experiments conducted, we proved that there is a high chance of breaking 8 - 10 character length passwords in a reasonable time. Dictionary and Attribute-Based attacks were proved to work in the wild based on cracking time and the number of compromised passwords in the datasets. Results show that it is possible to break the password standards using offline attacks and public user attributes in a reasonable time. A Machine Sensitive Key Based Password Strength Metric is then proposed based on the ratio of risk and safe probabilities of the password. The metric is based on the measurements gathered from the Brute Force, Dictionary and Attribute-Based Password Attacks.