SimHQ
Previous Thread
Next Thread
Print Thread
Rate Thread
Hop To
Joined: Nov 2005
Posts: 3,591
Likes: 41
Senior Member
Senior Member
Joined: Nov 2005
Posts: 3,591
Likes: 41
Researchers have built a Linux PC that takes just 5.5 hours to crack every possible eight-character password � including those containing upper- and lower-case letters, digits, and symbols:

http://arstechnica.com/security/2012/12/...ord-in-6-hours/

Last edited by RedToo; 02/18/16 11:36 AM. Reason: oops - just noticed the date stamp on that story - 2012!

My 'Waiting for Clod' thread: https://tinyurl.com/4n82j75z

Always take sides. Neutrality helps the oppressor, never the victim. Silence encourages the tormentor, never the tormented.
Elie Wiesel. Romanian born Jewish writer, professor, political activist, Nobel Laureate, Holocaust survivor. 1928 - 2016.

Indeed the safest road to Hell is the gradual one - the gentle slope, soft underfoot, without sudden turnings, without milestones, without signposts. C.S. Lewis, 1898 - 1963.
Inline advert (2nd and 3rd post)

Joined: Apr 2001
Posts: 125,018
Likes: 66
Pro-Consul of Florida
King Crimson - SimHQ's Top Poster
Pro-Consul of Florida
King Crimson - SimHQ's Top Poster
Joined: Apr 2001
Posts: 125,018
Likes: 66
Meh, I'm sure the NSA and FBI have had one of those PC's for a while now. wink


“Whoever fights monsters should see to it that in the process he does not become a monster. And if you gaze long enough into an abyss, the abyss will gaze back into you.�
Joined: Feb 2012
Posts: 783
F
Member
Member
F Offline
Joined: Feb 2012
Posts: 783
Can I get one? I forget my password occasionally...


combtpilot.co.uk
Joined: Jun 2009
Posts: 1,768
C
Member
Member
C Offline
Joined: Jun 2009
Posts: 1,768
Everytime i forget my passwords, i send a msg to NSA or GCHQ. No problem.

Joined: Apr 2001
Posts: 1,490
Likes: 1
C
Member
Member
C Offline
Joined: Apr 2001
Posts: 1,490
Likes: 1
Two step verification (by text) or the use of a password and token would be able to defeat that, I would think....and hope.

My bank allows my password to be a 4 digit code followed by a token number that changes every 60 seconds.


Intel i7-13700K
Gigabyte Z690 Aorus Ultra
Radeo RX 570 (8GB)

Joined: Feb 2000
Posts: 49,716
J
Entil'zha
Sierra Hotel
Entil'zha
Sierra Hotel
J Offline
Joined: Feb 2000
Posts: 49,716
The password is pretty much outdated. Whether it's easy to remember or not, it's about the same for a computer to crack.



The Jedi Master


The anteater is wearing the bagel because he's a reindeer princess. -- my 4 yr old daughter
Joined: Apr 2001
Posts: 125,018
Likes: 66
Pro-Consul of Florida
King Crimson - SimHQ's Top Poster
Pro-Consul of Florida
King Crimson - SimHQ's Top Poster
Joined: Apr 2001
Posts: 125,018
Likes: 66
Why haven't retinal and other biometric authentication methods become more widespread? I guess cost?


“Whoever fights monsters should see to it that in the process he does not become a monster. And if you gaze long enough into an abyss, the abyss will gaze back into you.�
Joined: Feb 2000
Posts: 49,716
J
Entil'zha
Sierra Hotel
Entil'zha
Sierra Hotel
J Offline
Joined: Feb 2000
Posts: 49,716
And reliability. A glitch can lock you out.

The USAF had retinal scanners at Cape Canaveral back in the 90s I think but they failed so often they dumped them for ID cards you swiped w/PINs.




The Jedi Master


The anteater is wearing the bagel because he's a reindeer princess. -- my 4 yr old daughter
Joined: Sep 2004
Posts: 5,943
K
Hotshot
Hotshot
K Offline
Joined: Sep 2004
Posts: 5,943
Originally Posted By: Catfish
Everytime i forget my passwords, i send a msg to NSA or GCHQ. No problem.



I ask Matt Wagner.

Joined: Jan 2011
Posts: 1,527
W
Member
Member
W Offline
Joined: Jan 2011
Posts: 1,527
Originally Posted By: Cajun
Two step verification (by text) or the use of a password and token would be able to defeat that, I would think....and hope.


Anything is able to defeat this. The article is highly sensationalist. The only particularly new thing here is the speed at which they generated each of the hashes.

It a) has nothing to do with password length, a 400 letters long password password would generate the same length in a hash and b) won't work in real life because pretty much 100% of the time NTLM authentication is done with a remote server. Which they of course didn't use, otherwise they wouldn't be able to achieve that speed.

What they did here is pretty much the same thing that has been done for ages. Attack the hash/key/you-named that is generated from people's passwords. That's why 64-bit algorithms are not used any more, that's why Microsoft Office's RC-40 was vulnerable, and that's the way encryption algorithms work. All of them. The name of the game is "delay" and not "prevent" breakage.


When you're feeling sad, just remember that somewhere in the world, there's someone pushing a door that says "pull".
Joined: Jan 2001
Posts: 25,177
Likes: 2
R
Lifer
Lifer
R Offline
Joined: Jan 2001
Posts: 25,177
Likes: 2
Yep, that attack requires them to get the password file first. Which is possible, but not so easy.

In any kind of client/server scenario the server will block repeated guesses, deactivate the account etc.

As the article says there are also newer hasl algorythms.

Joined: Dec 2001
Posts: 2,557
J
Senior Member
Senior Member
J Offline
Joined: Dec 2001
Posts: 2,557
The best password to use is "incorrect".
This way, if you forget it or type it in wrong, the computer will remind you.

Last edited by jack72; 02/18/16 06:26 PM.
Joined: Dec 2005
Posts: 1,876
I
SimHQ's resident fire enthusiast.
Member
SimHQ's resident fire enthusiast.
Member
I Offline
Joined: Dec 2005
Posts: 1,876
There you go.

https://xkcd.com/936/


"When I saw The Matrix at a local theatre in Slovenia, I had the unique opportunity of sitting close to the ideal spectator of the film - namely, to an idiot." - Slavoj Zizek
O
oselisan
Unregistered
oselisan
Unregistered
O
The internet is hell for a paranoid like me. I just got into the IT thing a few years ago and really can't keep up or am losing interest in keeping up.

It's like a stupid house. A determined person will find ways to get in. Smashing windows or with lock picks, maybe a freaking battering ram if no one's around. Eh while were at it, throw in some plastic explosives used by SWAT teams to break in.

Right now my stance is to get the basics right. The rest is trying to stay under the radar and not be a target.

Joined: Jun 2002
Posts: 5,555
V
Hotshot
Hotshot
V Offline
Joined: Jun 2002
Posts: 5,555
Notice it is able to crack Windows passwords, not ALL 8 digit passwords. WINDOWS passwords.

Windows is notorious for poor choices regarding encryption and security.

For example, Windows 7 uses MD4 encryption for passwords. This encryption method is SERIOUSLY outdated and was already insecure at the time Windows 7 was introduced. People have been cracking and bypassing them for years.


But one other thing...Windows passwords are useless. All someone needs to do is access your computer with a USB drive with Linux or some other OS on it. They can then see your entire hard drive. The Windows password only stops people from logging in, it does not encrypt your data. It is basically completely useless.

If you are paranoid about security, do an encrypted disk install of Linux and set a long, complicated password generated randomly.

I personally have an encrypted disk Kali Linux installation and I use the Tor browser and Tor network whenever I want to remain anonymous and secure, for example when discussing Japanese politics (JP government has been known to "disappear" people who oppose certain actions it has been conducting recently)

Using the Tor browser with a bridge is pretty much guaranteed security especially if you only use it at random wireless access points, even more so if you uhh...acquire the wireless keys outside of conventional means.

If you are a normal person who's not active in political leaks or you're not handling huge amounts of money, online privacy is not really something you should worry about. Hackers / Russian mob etc. do not care about you. They have higher priority targets. You should worry more about your computer being turned into a zombie for a botnet than worry about whether your name and address are somewhere online.

O
oselisan
Unregistered
oselisan
Unregistered
O
Reminded me of the Kali installation I still have on my laptop. Didn't remove it after the contract that required its use was finished.

Hmmm maybe I should take it for a spin just for fun... will need to review some basics.

Yes, I also keep reminding myself that I'm a nobody and hackers etc. have higher priorities. However, with my close relative's emails hacked, including acquaintances (almost everyone around me), I wish I could be 100% sure.

Last edited by oselisan; 02/19/16 11:35 AM.
Joined: Dec 2014
Posts: 3,552
C
Senior Member
Senior Member
C Offline
Joined: Dec 2014
Posts: 3,552
My password is invalid.

So I will never forget it.


Moderated by  RacerGT 

Link Copied to Clipboard
Quick Search
Recent Articles
Support SimHQ

If you shop on Amazon use this Amazon link to support SimHQ
.
Social


Recent Topics
God Forbid they want to have a bit of fun at work
by NoFlyBoy - 09/22/26 08:50 PM
How a 5" 38 Caliber US Naval Gun Works
by F4UDash4 - 09/19/26 01:20 AM
100% commission based sales
by PanzerMeyer - 09/18/26 04:47 PM
Relativity
by Terl9999 - 09/18/26 04:34 AM
HOA's
by Terl9999 - 09/18/26 04:12 AM
Football
by Terl9999 - 09/18/26 02:42 AM
Flags
by Terl9999 - 09/15/26 10:03 PM
September 15th Battle of Britain Day.
by RedToo - 09/15/26 08:06 PM
Population Patterns
by PanzerMeyer - 09/15/26 03:43 PM
"Problem occurred in connection"
by F4UDash4 - 09/14/26 01:41 PM
Popular Topics(Views)
7,068,716 SAM Simulator
Copyright 1997-2016, SimHQ Inc. All Rights Reserved.

Powered by UBB.threads™ PHP Forum Software 8.0.1