Password Duel
Summary

Overview
Do your students have their own online accounts like email or social media? What about a login for the school computers? If so, they might have to pick passwords. Have you ever had trouble creating (and forgetting) good passwords? This fun lesson plan involves a guessing game that can teach your students how to make their passwords harder to guess. Learn how to keep your accounts safe!Learning Objectives
- Understand that allowing more characters for a password results in more possible combinations for that password
- Demonstrate that a password with more possible combinations is harder to guess
Materials
- Stopwatch (one for entire class)
- Pencil and paper (for each student)
Background Information for Teachers
This section contains a quick review for teachers of the science and concepts covered in this lesson.You might be familiar with the rules most websites require for creating a "strong" password. They typically must be at least 8 characters long, and have various other requirements (for example, you must use at least one uppercase letter, one number, and maybe one symbol). These rules might seem silly, but there is reasoning behind them. Hackers know that certain types of passwords—especially ones that are all numbers (like "123456789") or all lowercase letters (like "qwerty," "abcdefgh," or "password")—are used commonly. They might try these passwords first when they attempt to break into someone's account. This is called a dictionary attack because it uses a "dictionary" of common passwords. Rules requiring that you use a mix of letters, numbers, and symbols force you to avoid these types of passwords.
What if a dictionary attack doesn't work? Hackers might try a brute force attack, or guessing every single possible password. For example, imagine that you are trying to crack a suitcase or bicycle lock with three number wheels, each one 0–9. You could try guessing every single possible combination by starting at 000, then 001, then 002, ...all the way up to 999. That will work eventually, but it will take you a while! It would take even longer if the lock had four or five number wheels. The same concept applies to computer passwords. For example, a two-character password, with only lowercase letters (26 letters in the English alphabet) has 26×26=262=676 possibilities for the password (for each possible choice for the first character, there are 26 possible choices for the second character). Any single attempt at randomly guessing the password only has a 1 out of 676 chance of being right. Including lower and upper case letters (52 possibilities for each character) yields 52×52=522=2,704 possibilities. Doubling the number of possible characters more than doubled the number of possible passwords! Now, any single guess only has a 1 out of 2,704 chance of being right. As you continue to add characters (e.g. numbers and symbols) and make the passwords longer, the number of possibilities becomes enormous (see Table 1). There are 95 characters on a standard English keyboard (counting upper/lowercase letters, numbers, and symbols). If your password has to be at least 8 characters long, that gives 958, or over six quadrillion possibilities!
| Number of possible password combinations for different character sets | ||||||
|---|---|---|---|---|---|---|
| Password length | Numbers only (0–9) | Examples | Lowercase letters only (a–z) | Examples | Upper/lowercase letters, numbers, symbols (a–z, A–Z, 0–9, @#$%...) | Examples |
| 1 | 10 | 3 | 26 | h | 95 | A |
| 2 | 100 | 45 | 676 | sh | 9,025 | h2 |
| 3 | 1,000 | 628 | 17,576 | iql | 857,375 | g%3 |
| 4 | 10,000 | 1973 | 456,976 | bqof | 81,450,625 | vL*6 |
| 5 | 100,000 | 14850 | 11,881,376 | lnkoq | 7,737,809,375 | r03@B |
| 6 | 1,000,000 | 355698 | 308,915,776 | zmpqla | 735,091,890,625 | a2&M1s |
| 7 | 10,000,000 | 8415268 | 8,031,810,176 | rvynimw | 69,833,729,609,375 | v98(Q!i |
| 8 | 100,000,000 | 82145669 | 208,827,064,576 | xwvrnymu | 6,634,204,312,890,620 | L3$7bv~0 |
In this project your students will split up into pairs and play a "guessing game" to simulate hackers trying to guess a password, except the game is not fair! One student must pick a number 0–9, (10 possibilities) as a "password," and the other student will pick a number or a letter; 0–9 or a–z (36 possibilities). So, when playing the game, one student has a 1 in 10 chance of guessing the password with any given guess, and the other student only has a 1 in 36 chance. You would never use a one-character password in real life, but this ensures that the game can be completed in a reasonable amount of time in a classroom setting. The game will demonstrate how allowing more choices for each character makes a password stronger, or more difficult to guess.
Additional Background Links
- Creating a Strong Password, Google
- List of the most common passwords, Wikipedia
- Password Recovery Speeds, Lockdown.co.uk
- Probability, MathIsFun
Prep Work (5 minutes)
- Print out student worksheets and quizzes if you plan to use them
Teacher Tool Box
Engage (5 minutes)
- Start the lesson with a discussion about students' online accounts and passwords.
What are some examples of online or computer accounts that you have?Answers might include email, social media or messaging (Facebook, Instagram, SnapChat, Twitter, etc.), or a computer login at home or at school.Do these accounts require passwords? Why? What could happen if someone else guessed one of your passwords?Passwords prevent other people from using your accounts. What happens if someone else gains access to your account can vary depending on the type of account. For example, somebody could post on social media or send emails pretending to be you, erase all your contacts, read all your personal messages, download personal photos from your phone, or steal items or money from an online video game.Imagine that you wanted to try and guess a friend's (Facebook/email/etc.) password. What strategies would you try?Let students come up with their own ideas. For example, they might try using information they know about that person (names of family members, pets, their birthday, etc.), because many people use such information as part of their passwords to make them easier to remember.What if you wanted to guess a stranger's password? Would your approach change at all?Guessing a stranger's password might be harder if you don't know much about them. You could try looking up information about them online so you could make educated guesses. You could also try guessing random passwords, or systematically guessing every possible password.
- Explain that they will now play a guessing game where they pair up and create "passwords" that their partner will try to guess. To keep the activity short, their "passwords" will only be one character long. One student in each group will select a number (0–9). The other student will select a number or a letter (0–9 or a–z).
Do you think one type of password will be harder to guess? Why? How could we find out?Let your students come up with their own ideas—do not give away the expected answer here! See the teacher background section if you need help understanding which type of password will be harder to guess.
Explore (15 minutes)
- Divide the class into pairs. If you have an odd number of students, put yourself in one of the pairs.
- Assign one student from each pair to group A, and one student from each pair to group B.
- Complete one round of the guessing game. For each pair of students:
- Students pick their passwords before the round starts and write them on the student worksheet (no peeking—keep the worksheet hidden from your partner!).
- Student A picks a number 0–9.
- Student B picks a number 0–9 or a letter a–z.
- Both students take turns trying to guess the other's password (first student A makes one guess, then student B makes one guess, etc.).
- As soon as one student guesses the other student's password, that student wins the round and guessing stops.
- Each student uses their worksheet to record which password was guessed (number only or letter/number).
- Students pick their passwords before the round starts and write them on the student worksheet (no peeking—keep the worksheet hidden from your partner!).
- Make a table on the board like Table 2. Keep a running tally mark for the entire class for how many times each type of password was guessed first.
- Ask one student from each group to raise their hand if their number-only password was guessed first. Tally the raised hands.
- Ask one student from each group to raise their hand if their letter or number password was guessed first. Tally the raised hands.
| Password type | Total number of times password was guessed first |
|---|---|
| Number only (0–9) | |
| Number or letter (0–9 or a–z) |
- Repeat steps 3–4, but let group B guess first.
- Switch the rules for groups A and B (now group A picks a number or letter password, and group B picks a number-only password), and repeat steps 3–5.
- If you have a small class or group (~10 students or less), repeat steps 3–6 to make sure you have enough data. If you have extra time, you can do additional rounds just for fun. The student worksheet contains space for up to 8 rounds.
Reflect (10 minutes)
- Examine the results you tallied on the board.
What do our results show?Your results should show that the number-only password was guessed first the majority of the time (roughly 80% of the time, although the exact amount will vary due to the random nature of the activity). If your results do not clearly show this, try doing a few more rounds of the game to get more data (explain to your students that in the real world, scientists might repeat experiments if they get unexpected results, to make sure they did not make any mistakes).What does this tell us? Was one type of password easier to guess than the other?This shows us that the number-only password was easier to guess than the number/letter password. If both types of passwords were equally difficult to guess, we would have expected to guess both types about the same number of times. One type being guessed more shows that it was easier to guess.Why does this occur? Do the rules for creating the password affect how difficult it is to guess?This occurs because the number of total possible passwords for each type was different. For a number-only password, there are only 10 possible passwords. So, any one guess has a 1 in 10 chance of being right. For a number/letter password, there are 36 possible passwords (10 numbers + 26 letters). Any one guess only has a 1 in 36 chance of being right, so this type of password is relatively harder to guess.
- Now, discuss how this activity applies to real-life passwords and cybersecurity.
Did anyone employ any guessing strategies during the game? If so, what strategies? Do you think they worked?Students might have tried different strategies, other than just guessing randomly. For example, they might have always guessed the numbers/letters in order, they might have only guessed odd numbers first, they might have tried to guess their partner's "favorite" number or letter, etc.How could we make the passwords in our guessing game even harder to guess? Would this make your guessing strategies more difficult?We could include other characters, like uppercase letters and punctuation. For example, adding uppercase letters adds 26 more possibilities, bringing the total up to 62. We could also make the passwords longer. For example, if we use a 2-digit number instead of a 1-digit number, there are 100 possibilities instead of 10. This could make some of the guessing strategies much harder—for example, it would take 10 times as long to guess all possibilities for a 2-digit number instead of a 1-digit number.Real passwords are always longer than just 1 character, so they can take a very long time to guess by hand. What type of strategies do you think real hackers use when trying to guess someone's password?Real hackers have several techniques they use to guess passwords. One method is to try guessing very common words or phrases that lots of people use because they are easy to remember. Examples include things like "password," "123456789," or "qwerty." This is called a "dictionary attack" because it uses a dictionary of common passwords. Another method is to cycle through all possible password combinations. For example, for a 4-digit PIN on somebody's phone or for an ATM card, you would start out with 0001, then 0002, all the way up to 9999. This is called a "brute force attack."Does anyone know the rules most websites require for real passwords? Can you explain why they have these rules, based on what we just learned in this activity? How do these rules help keep you safe from real-world hackers?Most websites require that passwords be at least eight characters long, and contain a mix of upper/lowercase letters, numbers, and symbols. This helps keep us safe from both dictionary and brute-force attacks. For example, it prevents you from using a password that is all lowercase letters, which may be easier for hackers to guess with a brute force attack. It also rules out many of the common passwords used in dictionary attacks.
- End the lesson with a more general discussion about passwords and online safety.
Does anyone know some other safety rules we should follow when creating and using passwords? How do these rules help keep us safe from hackers?These general rules help keep your accounts safe from anonymous online hackers and people you might know in real life (like a disgruntled classmate or coworker).
- Do not share your passwords with anyone (except your parents).
- Do not write your passwords down—you could lose the paper or someone could steal it.
- Avoid using obvious patterns, even if they include a mix of different character types, because these may be included in dictionary attacks (e.g. "a1b2c3d4").
- Avoid using common number/symbol substitutions for letters (e.g. "$" for "s," "3" for "e"), as these substitutions may also be included in dictionary attacks.
- Avoid including personal information in your password, even if you mix numbers, letters, and symbols. For example, if your dog's name is Fido and your birthday is July 20th, 2005, then Fido72005! is probably not a good password.
Assess
You can use this quiz to assess student learning after the activity:
- Online quiz, assignable in any LMS
- Quiz (pdf) and answer key (PDF)
Make Career Connections
Discussing or reading about these careers can help students make important connections between the in-class lesson and STEM job opportunities in the real world.








