(Press-News.org) PITTSBURGH—When writing or speaking, good grammar helps people make themselves be understood. But when used to concoct a long computer password, grammar — good or bad — provides crucial hints that can help someone crack that password, researchers at Carnegie Mellon University have demonstrated.
A team led by Ashwini Rao, a software engineering Ph.D. student in the Institute for Software Research, developed a password-cracking algorithm that took into account grammar and tested it against 1,434 passwords containing 16 or more characters. The grammar-aware cracker surpassed other state-of-the-art password crackers when passwords had grammatical structures, with 10 percent of the dataset cracked exclusively by the team's algorithm.
"We should not blindly rely on the number of words or characters in a password as a measure of its security," Rao concluded. She will present the findings on Feb. 20 at the Association for Computing Machinery's Conference on Data and Application Security and Privacy (CODASPY 2013) in San Antonio, Texas.
Basing a password on a phrase or short sentence makes it easier for a user to remember, but the grammatical structure dramatically narrows the possible combinations and sequences of words, she noted.
Likewise, grammar, whether good or bad, necessitates using different parts of speech — nouns, verbs, adjectives, pronouns — that also can undermine security. That's because pronouns are far fewer in number than verbs, verbs fewer than adjectives and adjectives fewer than nouns. So a password composed of "pronoun-verb-adjective-noun," such as "Shehave3cats" is inherently easier to decode than "Andyhave3cats," which follows "noun-verb-adjective-noun." A password that incorporated more nouns would be even more secure.
"I've seen password policies that say, 'Use five words,'" Rao said. "Well, if four of those words are pronouns, they don't add much security."
For instance, the team found that the five-word passphrase "Th3r3 can only b3 #1!" was easier to guess than the three-word passphrase "Hammered asinine requirements." Neither the number of words nor the number of characters determined password strength when grammar was involved. The researchers calculated that "My passw0rd is $uper str0ng!" is 100 times stronger as a passphrase than "Superman is $uper str0ng!," which in turn is 10,000 times stronger than "Th3r3 can only b3 #1!"
The research was an outgrowth of a class project for a masters-level course at CMU, Rao said. She and Gananand Kini, a fellow CMU graduate student, and Birendra Jha, a Ph.D. student at MIT, built their password cracker by building a dictionary for each part of speech and identifying a set of grammatical sequences, such as "determiner-adjective-noun" and "noun-verb-adjective-adverb," that might be used to generate passphrases.
Rao said the grammar-aware password cracker was intended only as a proof of concept and no attempt has been made to optimize its performance. But it is only a matter of time before someone does, she predicted.
###
The Institute for Software Research is part of CMU's School of Computer Science. Follow the school on Twitter @SCSatCMU.
About Carnegie Mellon University: Carnegie Mellon (www.cmu.edu) is a private, internationally ranked research university with programs in areas ranging from science, technology and business, to public policy, the humanities and the arts. More than 11,000 students in the university's seven schools and colleges benefit from a small student-to-faculty ratio and an education characterized by its focus on creating and implementing solutions for real problems, interdisciplinary collaboration and innovation. A global university, Carnegie Mellon's main campus in the United States is in Pittsburgh, Pa. It has campuses in California's Silicon Valley and Qatar, and programs in Africa, Asia, Australia, Europe and Mexico. The university is in the midst of "Inspire Innovation: The Campaign for Carnegie Mellon University," which aims to build its endowment, support faculty, students and innovative research, and enhance the physical campus with equipment and facility improvements.
Grammar undercuts security of long computer passwords
Carnegie Mellon researchers devise grammar-aware password cracker
2013-01-24
ELSE PRESS RELEASES FROM THIS DATE:
Neuroinflammation may be behind general-anesthesia-associated learning disabilities
2013-01-24
Several studies have found evidence that children who undergo repeated surgical operations with general anesthesia before the age of 4 may be at an increased risk for learning disabilities. In the March issue of Anesthesiology, Massachusetts General Hospital (MGH) researchers report an animal study indicating that several factors – age, the specific anesthetic agent used and the number of doses – combine to induce impairments in learning and memory accompanied by the inflammation of brain tissue. An accompanying paper from the same team finds that the offspring of mice ...
Urban metabolism for the urban century
2013-01-24
New Haven, Conn.–Like organisms, cities need energy, water, and nutrients, and they need to dispose of wastes and byproducts in ways that are viable and sustainable over the long run. This notion of "urban metabolism" is a model for looking systematically at the resources that flow into cities and the wastes and emissions that flow out from them—to understand the environmental impacts of cities and to highlight opportunities for efficiencies, improvements, and transformation.
Yale University's Journal of Industrial Ecology is pleased to announce a special issue on Sustainable ...
New dinosaur fossil challenges bird evolution theory
2013-01-24
The discovery of a new bird-like dinosaur from the Jurassic period challenges widely accepted theories on the origin of flight.
Co-authored by Dr Gareth Dyke, Senior Lecturer in Vertebrate Palaeontology at the University of Southampton, the paper describes a new feathered dinosaur about 30 cm in length which pre-dates bird-like dinosaurs that birds were long thought to have evolved from.
Over many years, it has become accepted among palaeontologists that birds evolved from a group of dinosaurs called theropods from the Early Cretaceous period of Earth's history, around ...
Sun shoots out 2 coronal mass ejections
2013-01-24
VIDEO:
This movie shows two coronal mass ejections (CMEs) erupting from the sun on Jan. 23, 2013. The first was not directed at Earth; the second one is, but is not...
Click here for more information.
On Jan. 23, 2013, at 9:55 a.m. EST, the sun erupted with an Earth-directed coronal mass ejection, or CME. Experimental NASA research models, based on observations from the Solar Terrestrial Relations Observatory (STEREO) and ESA/NASA's Solar and Heliospheric Observatory, show ...
Valuing nature is not enough
2013-01-24
Is it possible to put a price tag on the natural world? A researcher at The University of Nottingham has been examining the rise of a new concept — ecosystem services — to describe the multitude of resources supplied to us by Mother Nature.
Academic Dr Marion Potschin, of the University's Centre for Environmental Management, is among an international team of researchers who have been investigating the ethical considerations of this new concept, which some have argued turns nature into a 'commodity'.
In a paper published in the journal BioScience, Dr Potschin and her ...
Cells 'flock' to heal wounds
2013-01-24
Like flocks of birds, cells coordinate their motions as they race to cover and ultimately heal wounds to the skin. How that happens is a little less of a mystery today.
Researchers once thought only the cells at the edge of a growing patch of wounded skin were actively moving while dividing cells passively filled in the middle. But that's only part of the picture. Rice University physicist Herbert Levine and his colleagues have discovered that the process works much more efficiently if highly activated cells in every part of the patch exert force as they pull their neighbors ...
UCI neuroscientists create fiber-optic method of arresting epileptic seizures
2013-01-24
Irvine, Calif., Jan. 24, 2013 — UC Irvine neuroscientists have developed a way to stop epileptic seizures with fiber-optic light signals, heralding a novel opportunity to treat the most severe manifestations of the brain disorder.
Using a mouse model of temporal lobe epilepsy, Ivan Soltesz, Chancellor's Professor and chair of anatomy & neurobiology, and colleagues created an EEG-based computer system that activates hair-thin optical strands implanted in the brain when it detects a real-time seizure.
These fibers subsequently "turn on" specially expressed, light-sensitive ...
Mouse menopause model sheds light on UTIs in post-menopausal women
2013-01-24
Researchers from Washington University School of Medicine, St. Louis, show that reservoirs of uropathogenic E. coli within the bladder exist in higher numbers post-menopause than pre-menopause in a mouse model, a finding that could help explain the greater prevalence of urinary tract infections in post-menopausal women. They also found that estrogen supplementation reduced the numbers of such reservoirs dramatically. The research was published online ahead of print in the journal Infection and Immunity.
Urinary tract infections (UTIs) afflict an estimated 13 million ...
Vocabulary instruction failing US students
2013-01-24
EAST LANSING, Mich. — Vocabulary instruction in the early years is not challenging enough to prepare students for long-term reading comprehension, argues a study led by a Michigan State University education researcher.
The study, which appears in Elementary School Journal, analyzed commonly used reading curricula in U.S. kindergarten classrooms. It found that, generally, the programs do not teach enough vocabulary words; the words aren't challenging enough; and not enough focus is given to make sure students understand the meaning of the words.
"Vocabulary instruction ...
Research: Lupus drugs carry no significant cancer risk for patients
2013-01-24
This press release is available in French.
Montreal, January 24, 2013 – People who take immunosuppressive drugs to treat lupus do not necessarily increase their cancer risk according to new research led by scientists at the Research Institute of the McGill University Health Centre (RI-MUHC). This landmark study, which was published in Annals of the Rheumatic Diseases this month, addresses long-standing fears of a link between lupus medication and cancer.
Systemic lupus erythematosus (SLE), commonly known as lupus, is an autoimmune disease in which the body's immune ...
LAST 30 PRESS RELEASES:
ASU researchers to lead AAAS panel on water insecurity in the United States
ASU professor Anne Stone to present at AAAS Conference in Phoenix on ancient origins of modern disease
Proposals for exploring viruses and skin as the next experimental quantum frontiers share US$30,000 science award
ASU researchers showcase scalable tech solutions for older adults living alone with cognitive decline at AAAS 2026
Scientists identify smooth regional trends in fruit fly survival strategies
Antipathy toward snakes? Your parents likely talked you into that at an early age
Sylvester Cancer Tip Sheet for Feb. 2026
Online exposure to medical misinformation concentrated among older adults
Telehealth improves access to genetic services for adult survivors of childhood cancers
Outdated mortality benchmarks risk missing early signs of famine and delay recognizing mass starvation
Newly discovered bacterium converts carbon dioxide into chemicals using electricity
Flipping and reversing mini-proteins could improve disease treatment
Scientists reveal major hidden source of atmospheric nitrogen pollution in fragile lake basin
Biochar emerges as a powerful tool for soil carbon neutrality and climate mitigation
Tiny cell messengers show big promise for safer protein and gene delivery
AMS releases statement regarding the decision to rescind EPA’s 2009 Endangerment Finding
Parents’ alcohol and drug use influences their children’s consumption, research shows
Modular assembly of chiral nitrogen-bridged rings achieved by palladium-catalyzed diastereoselective and enantioselective cascade cyclization reactions
Promoting civic engagement
AMS Science Preview: Hurricane slowdown, school snow days
Deforestation in the Amazon raises the surface temperature by 3 °C during the dry season
Model more accurately maps the impact of frost on corn crops
How did humans develop sharp vision? Lab-grown retinas show likely answer
Sour grapes? Taste, experience of sour foods depends on individual consumer
At AAAS, professor Krystal Tsosie argues the future of science must be Indigenous-led
From the lab to the living room: Decoding Parkinson’s patients movements in the real world
Research advances in porous materials, as highlighted in the 2025 Nobel Prize in Chemistry
Sally C. Morton, executive vice president of ASU Knowledge Enterprise, presents a bold and practical framework for moving research from discovery to real-world impact
Biochemical parameters in patients with diabetic nephropathy versus individuals with diabetes alone, non-diabetic nephropathy, and healthy controls
Muscular strength and mortality in women ages 63 to 99
[Press-News.org] Grammar undercuts security of long computer passwordsCarnegie Mellon researchers devise grammar-aware password cracker


