I don't necessarily want insolence being trivially linked to my real life account, hence the throwaway.
There are some issues:
First, what he says is that "password crackers are on to this trick". Knowing the trick doesn't automatically render a scheme ineffectual. If it did, public key crypto wouldn't work (and the proposed scheme for generating passwords wouldn't be any better, anyway).
Second, the article he's citing is an Ars one about the state of the art in password cracking in 2013, which gave a flawed synthesis about the XKCD/diceware scheme based on a misunderstanding of it. Take a look at the list of cracked passwords given as examples, and see if you can find a single one that would have been generated using that scheme.
One of the main takeaways of the Ars article was that the XKCD/diceware scheme is broken. A reference to the XKCD strip is featured prominently in the the main graphic, but the mention of it only shows up on page 3. Examining their methods shows the link from their methods to their conclusion to be a tenuous one. Calling it tenuous is actually being generous, because it's more like a false link. Here's where it gets called out:
Early in the process, Steube couldn't help
remarking when he noticed one of the plains he had
recovered was "momof3g8kids."
[...] Other times, they combine
words from one big dictionary with words from a
smaller one. Steube was able to crack
"momof3g8kids" because he had "momof3g" in his 111
million dict and "8kids" in a smaller dict.
"The combinator attack got it! It's cool," he
said. Then referring to the oft-cited xkcd comic,
he added: "This is an answer to the
batteryhorsestaple thing."
This suggests that the cracker doesn't understand what the comic strip is advising readers to do when generating passwords.
Now some closing remarks about this research in general. When the Ars article was published I waited for someone to call it out, but didn't find anyone doing that. I waited some time to look again and turned up nothing. That is disappointing, but fine, I suppose.
However, the particular way that the security community builds up reverence for individuals and discourages re-examining past results is troubling. When I see how big of an effect the conclusions of one guy and the journalist that wrote about him in a popsci news source have, and when I see that some people have an itch to challenge those conclusions but don't put them out there, I'm reminded respectively of Feynman's motivation to write about cargo cult science and to warn us against the kinds of things that happened with Millikan's results and the oil drop experiment. People shouldn't feel they need to turn away from an argument just because they see those on the other side citing Schneier, and the community needs to do better about not encouraging the growth of unassailable celebrity or creating sacred cows.
There are some issues:
First, what he says is that "password crackers are on to this trick". Knowing the trick doesn't automatically render a scheme ineffectual. If it did, public key crypto wouldn't work (and the proposed scheme for generating passwords wouldn't be any better, anyway).
Second, the article he's citing is an Ars one about the state of the art in password cracking in 2013, which gave a flawed synthesis about the XKCD/diceware scheme based on a misunderstanding of it. Take a look at the list of cracked passwords given as examples, and see if you can find a single one that would have been generated using that scheme.
One of the main takeaways of the Ars article was that the XKCD/diceware scheme is broken. A reference to the XKCD strip is featured prominently in the the main graphic, but the mention of it only shows up on page 3. Examining their methods shows the link from their methods to their conclusion to be a tenuous one. Calling it tenuous is actually being generous, because it's more like a false link. Here's where it gets called out:
This suggests that the cracker doesn't understand what the comic strip is advising readers to do when generating passwords.
Now some closing remarks about this research in general. When the Ars article was published I waited for someone to call it out, but didn't find anyone doing that. I waited some time to look again and turned up nothing. That is disappointing, but fine, I suppose.
However, the particular way that the security community builds up reverence for individuals and discourages re-examining past results is troubling. When I see how big of an effect the conclusions of one guy and the journalist that wrote about him in a popsci news source have, and when I see that some people have an itch to challenge those conclusions but don't put them out there, I'm reminded respectively of Feynman's motivation to write about cargo cult science and to warn us against the kinds of things that happened with Millikan's results and the oil drop experiment. People shouldn't feel they need to turn away from an argument just because they see those on the other side citing Schneier, and the community needs to do better about not encouraging the growth of unassailable celebrity or creating sacred cows.