HUMAN-GENERATED SECRET DATA
Joseph Bonneau jcb82@cl.cam.ac.uk
Computer Laboratory Security and Human Behaviour Cambridge, UK June 29, 2010
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 1 / 15
The Simple English guide to human-generated secrets Computers try to - - PowerPoint PPT Presentation
H UMAN - GENERATED SECRET DATA Joseph Bonneau jcb82@cl.cam.ac.uk Computer Laboratory Security and Human Behaviour Cambridge, UK June 29, 2010 Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 1 / 15 The Simple English
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 1 / 15
1
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 2 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 2 / 15
1
2
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 3 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 4 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 4 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 5 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 6 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 7 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 7 / 15
Human secrets June 29, 2010 8 / 15
2
4
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 9 / 15
0.0 0.2 0.4 0.6 0.8 1.0 success rate α 1 2 3 4 5 6 7 8 marginal guesswork ˜ µα
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 10 / 15
0.0 0.2 0.4 0.6 0.8 1.0 success rate α 5 10 15 20 25 marginal guesswork ˜ µα
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 10 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 11 / 15
1
2
3
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 12 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 13 / 15
0.0 0.2 0.4 0.6 0.8 1.0 success rate α 5 10 15 20 25 30 35 40 marginal guesswork ˜ µα
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 13 / 15
0.0 0.2 0.4 0.6 0.8 1.0 success rate α 5 10 15 20 25 30 35 40 marginal guesswork ˜ µα
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 13 / 15
1
2
3
4
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 14 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 15 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 15 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 15 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 15 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 15 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 15 / 15
0.0 0.2 0.4 0.6 0.8 1.0 success rate α 5 10 15 20 25 30 35 40 marginal guesswork ˜ µα
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 15 / 15
1
2
3
4
5
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 16 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 17 / 15
2000 4000 6000 8000 10000 PIN 5 10 15 20 − log2 p(PIN)
0000 7171 3333 6666 2007 9999 2323 9494 5656 8989 5150 4869 1313 0808 5678 3636 6969 6464 0065 7777 8520 2121 9292 5454 8888 1111 7000 8282 4444 0607 8080 4200 6000 7272 9595 3456 6789 5254 5000 4747 6288 9876 0405 7575 3737 3232 2468 2727 9898 1010 2222 9393 5555 1717 3000 1212 5566 8383 4000 1234 4567 9696 4321 5858 0123 9191 1515 7890 9000 7410 8181 0506 7676 8701 3838 1858 6052 0838 9961 9066 7058 3062 8439 4764 3934
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 17 / 15
00 05 10 15 20 25 30 35 40 45 50 55 60 65 70 75 80 85 90 95
First two PIN digits
00 05 10 15 20 25 30 35 40 45 50 55 60 65 70 75 80 85 90 95
Second two PIN digits 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 − log2 p(PIN)
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 17 / 15
0.0 0.2 0.4 0.6 0.8 1.0 success rate α 5 10 15 20 25 30 35 40 marginal guesswork ˜ µα
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 17 / 15
0.0 0.2 0.4 0.6 0.8 1.0 success rate α 5 10 15 20 25 30 35 40 marginal guesswork ˜ µα
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 17 / 15
0.0 0.2 0.4 0.6 0.8 1.0 success rate α 5 10 15 20 25 30 35 40 marginal guesswork ˜ µα
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 17 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 17 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 16 / 15
Joseph Bonneau (University of Cambridge) Human secrets June 29, 2010 15 / 15