How Hackers Actually Crack Passwords (and Why Length Beats Symbols)

Most people picture a hacker typing guesses into a login box until it lets them in. That almost never happens. Real password cracking is automated, happens offline, and works because people choose passwords in predictable ways. Knowing how it works shows you what actually protects you.

Step one: get a copy of the database

Login forms limit attempts and lock accounts, so attackers go after a breached database instead: a copy of a service's user table, with usernames, emails and password hashes. With their own copy they can try guesses as fast as their hardware allows, with no limits and nobody watching.

Hashing: the protection you cannot see

A service should not store your password, only a hash, a one-way fingerprint. When you log in, it hashes what you type and compares. How well that protects you depends on the algorithm:

  • MD5 and SHA-1 are fast, which is exactly wrong for passwords. A modern GPU can test on the order of 100 billion MD5 hashes per second.
  • bcrypt, scrypt and Argon2 are deliberately slow. The same hardware may manage only thousands to hundreds of thousands of guesses per second, depending on the settings.

You cannot tell which one a service uses until it has a breach.

Dictionaries and rules beat brute force

Trying every combination only works for short passwords. Attackers do something smarter: they start with wordlists built from earlier breaches, common words and names, song lyrics, keyboard patterns like qwerty, and number sequences. Then they apply rules automatically: capitalize the first letter, add 1 or 123 or a year at the end, swap a for 4 and o for 0, reverse the word, double it.

That is why P@ssw0rd! is not strong. It is the word "password" with the most common substitutions and a symbol on the end, which sits among the first rules every tool tries. Rules like "must contain a capital, a number and a symbol" make passwords look harder without making them less predictable.

Rainbow tables and salt

For very common passwords, an attacker may not need to compute anything. A rainbow table is a precomputed list of hashes and their passwords, so recovering 123456 is a lookup. A salt, a random value added before hashing, makes every hash unique and makes those tables useless. Whether a service salts its hashes is again out of your hands.

What the numbers look like

This is the time to try every possible password of a given kind, so on average a successful guess comes in about half that time. It assumes truly random characters, a fast hash at 100 billion guesses per second, and a slow hash at 100,000 per second as a rough figure.

PasswordPossible passwordsFast hashSlow hash
8 lowercase letters2.1 × 1011about 2 secondsabout 24 days
8 letters (both cases) and digits2.2 × 1014about 36 minutesabout 69 years
12 random characters, letters, digits and symbols4.8 × 1023about 150,000 yearsover 100 billion years
16 random characters, letters, digits and symbols3.7 × 1031over 10 trillion yearsfar beyond any time frame

Two things stand out. A short password falls in seconds or minutes behind a fast hash, and even a slow hash only holds an 8-letter lowercase password for weeks. And length helps far more than extra symbols. These figures also only hold for random passwords: a password made of real words or patterns falls to the wordlist attacks above, long before the numbers in this table.

What to do

  • Use a long, randomly generated password, 16 characters or more, for each site, and let a password manager remember it.
  • Never reuse a password, so one leak cannot open your other accounts.
  • Turn on two-factor authentication for the accounts that matter.

Generate one in your browser (nothing is sent or stored) with the password generator, check one with the strength checker, or read the longer article, How Hackers Actually Crack Passwords.

More from ficklestudio26: see everything in one place.

Comments

Popular posts from this blog

클로드 사용량 위젯 배포 (Mac)