The SXWVN Website

May Journal: Day Thirty

May 30, 2025

The journal officially concludes now and here. Congratulations internet people, you have found one piece of information about me, yay. In fact, birthdays are very useful to get into someone’s device or account. Why? because it’s a hell lot easier to use “3005” or “0530” as a password than “qrZ+&d=r?7Ek28:2!Q>1CaN” or “Haiku!Level!Conclude!Unsmooth!Payroll!Repressed!Snowdrift!Auction!Puzzling”.

If you google “people using their birthday as their passwords” or something along the lines, you will find an old (2019) survey by Google and Harris Poll. Sucks that it’s only in the US and it’s from almost 6 years ago, but it’s still concerning to learn that more than half Americans incorporate their birthdays in their passwords.

Still talking about passwords and bad habits, did you know that people also use song lyrics as part of their passwords? Now this, I have to admit sometimes I’m guilty of. Why? Because passwords are hard to remember, but passphrases are not. It’s gonna be a hell lot easier and quicker to remember and type “IWasAlwaysOnYourSide608” than “3arZ+>?r?7oP28:2!Q>1CaNoq”, right? Sure, I have a password manager capable of auto-filling my credentials that I can unlock with biometrics for easier access. However, password made from lyrics of a song that always make me cry? Fucking easier!

Even with all of those precautions, is your password safe? Assuming the passwords stored by the applications or services you use are hashed and salted, are they safe for a long time? In cyber security, there is a term to describe the strategy often used to “crack” encryption and obfuscation that depends on quantum computing, called Steal Now, Decrypt Later. Bad actors can download encrypted password (or even other forms of encrypted data!) from data breaches. They can then use quantum computers to break the encryption. How is that possible? Because when you have deterministic algorithms based on prime number mathematical operations (which most encryption scheme you’ve heard of depend on anyways), you can just “guess” the big prime numbers (p and q or the equivalent of them). The strength of these algorithms depend on the fact that it’s hard to do this brute-forcing attack using “normal” every day computers. But quantum computers? That can hold and process more bits of information using qubit, that’s easy task for them. This has led cryptography researches to find an algorithm that’s supposed to be “quantum resistent”. As for the average users, should you worry about this? Eh, maybe not? I mean as long as you rotate your passwords, not reuse the same password, turn on MFA, or even ditch passwords altogether by using alternatives like passkeys, you should be safe. Maybe.

Ah yes, the average SXWVN blog experience. She started with a simple premise but ended up going off track.