Suspicious Website Logins
The table below is nine days of sign-in history for one account on the membership site bikeshare.example.org. The ⋮ row stands for 45 rows like the ones around it. This lesson finds the rows the account holder didn't make, and how the adversary behind them got in.
| Date | Time | Device | Result |
|---|---|---|---|
| Sat, Sep 12 | 8:05:31 a.m. | Phone app | Success |
| Sat, Sep 12 | 6:40:12 p.m. | Phone app | Success |
| Sun, Sep 13 | 9:12:48 a.m. | Tablet | Success |
| Thu, Sep 17 | 10:50:02 a.m. | Chromebook | Failed |
| Thu, Sep 17 | 10:50:05 a.m. | Chromebook | Failed |
| Thu, Sep 17 | 10:50:08 a.m. | Chromebook | Failed |
| ⋮ | ⋮ | ⋮ | ⋮ |
| Thu, Sep 17 | 10:52:26 a.m. | Chromebook | Failed |
| Thu, Sep 17 | 10:52:29 a.m. | Chromebook | Success |
| Sat, Sep 19 | 8:20:15 a.m. | Phone app | Success |
| Sun, Sep 20 | 9:45:02 a.m. | Tablet | Success |
Reading the log
The holder rides on weekends, signing in from a phone on Saturdays and a tablet on Sundays, always between 8 a.m. and 7 p.m.
The Thursday rows break that routine. A Chromebook appears for the first time, and the holder has never used one. Its first attempt came just after 10:50 a.m. The first 49 failed, and the 50th, 147 seconds after the first, succeeded. That's one attempt every 3 seconds.
Fifty attempts at a steady pace, each one wrong until the last, point to a program working through a list of guesses.
The Thursday rows show all three. Forty-nine failures in under two and a half minutes are many failed attempts over a short duration. A Thursday morning is unusual for an account used only on weekends. And the Chromebook is an unknown device. Since the last attempt worked, the adversary is now signed in.
Where the guesses came from
The log doesn't record the passwords typed. We know only the last guess, the holder's password
Pepper19!, because it worked. It's the dog's name, then 19 for 2019, the year the dog came home, then an exclamation point. The holder's public posts mention both the name and the year.The holder's password fits all three patterns.
The holder's posts name the dog and two family members and mention six years. Suppose the adversary's tool ends every guess with one of three characters: !, #, or @. Each guess then takes one of the three names, one of the six years as two digits, and one of those endings. That makes 3 × 6 × 3 = 54 guesses.
Pepper19! is one of them. At one attempt every 3 seconds, the tool could submit all 54 in under three minutes.The other two sources need no dictionary. A list of common passwords needs no information about the holder, and if the holder had used
Pepper19! on a site whose passwords were stolen, one attempt would have been enough.Stronger passwords
Every piece of
Pepper19! came from a common pattern or from the holder's posts. It's also only nine characters long, and none of them was chosen at random.A password manager might generate
jysD!!zr3Wsrnl2fpEc% for this account. Its twenty random characters hold no name or date, so no dictionary built from the posts contains it, and it isn't a common password.A 23-character passphrase such as
napkin-hat-shovel-towel works the same way when its four words are picked at random from a long word list: none comes from the posts, and there are far more combinations than an online attack could try. Each is also unique, so no other site's stolen passwords include it.Multifactor authentication
The second defense adds a step to signing in, after the password.
Suppose the site sends each one-time code to the holder's phone app. A correct password from the Chromebook is then only the first step. The site asks the Chromebook for the code, and the code goes to a phone the adversary doesn't have.