|
|
Joined: Nov 2005
Posts: 3,591 Likes: 41
Senior Member
|
|
Senior Member
Joined: Nov 2005
Posts: 3,591 Likes: 41 |
Researchers have built a Linux PC that takes just 5.5 hours to crack every possible eight-character password � including those containing upper- and lower-case letters, digits, and symbols: http://arstechnica.com/security/2012/12/...ord-in-6-hours/
Last edited by RedToo; 02/18/16 11:36 AM. Reason: oops - just noticed the date stamp on that story - 2012!
My 'Waiting for Clod' thread: https://tinyurl.com/4n82j75zAlways take sides. Neutrality helps the oppressor, never the victim. Silence encourages the tormentor, never the tormented.Elie Wiesel. Romanian born Jewish writer, professor, political activist, Nobel Laureate, Holocaust survivor. 1928 - 2016. Indeed the safest road to Hell is the gradual one - the gentle slope, soft underfoot, without sudden turnings, without milestones, without signposts. C.S. Lewis, 1898 - 1963.
|
|
|
|
|
Joined: Apr 2001
Posts: 125,018 Likes: 66
Pro-Consul of Florida King Crimson - SimHQ's Top Poster
|
|
Pro-Consul of Florida King Crimson - SimHQ's Top Poster
Joined: Apr 2001
Posts: 125,018 Likes: 66 |
Meh, I'm sure the NSA and FBI have had one of those PC's for a while now. 
“Whoever fights monsters should see to it that in the process he does not become a monster. And if you gaze long enough into an abyss, the abyss will gaze back into you.�
|
|
|
|
|
Joined: Feb 2012
Posts: 783
Member
|
|
Member
Joined: Feb 2012
Posts: 783 |
Can I get one? I forget my password occasionally...
combtpilot.co.uk
|
|
|
|
|
Joined: Jun 2009
Posts: 1,768
Member
|
|
Member
Joined: Jun 2009
Posts: 1,768 |
Everytime i forget my passwords, i send a msg to NSA or GCHQ. No problem.
|
|
|
|
|
Joined: Apr 2001
Posts: 1,490 Likes: 1
Member
|
|
Member
Joined: Apr 2001
Posts: 1,490 Likes: 1 |
Two step verification (by text) or the use of a password and token would be able to defeat that, I would think....and hope.
My bank allows my password to be a 4 digit code followed by a token number that changes every 60 seconds.
Intel i7-13700K Gigabyte Z690 Aorus Ultra Radeo RX 570 (8GB)
|
|
|
|
|
Joined: Feb 2000
Posts: 49,716
Entil'zha Sierra Hotel
|
|
Entil'zha Sierra Hotel
Joined: Feb 2000
Posts: 49,716 |
The password is pretty much outdated. Whether it's easy to remember or not, it's about the same for a computer to crack.
The Jedi Master
The anteater is wearing the bagel because he's a reindeer princess. -- my 4 yr old daughter
|
|
|
|
|
Joined: Apr 2001
Posts: 125,018 Likes: 66
Pro-Consul of Florida King Crimson - SimHQ's Top Poster
|
|
Pro-Consul of Florida King Crimson - SimHQ's Top Poster
Joined: Apr 2001
Posts: 125,018 Likes: 66 |
Why haven't retinal and other biometric authentication methods become more widespread? I guess cost?
“Whoever fights monsters should see to it that in the process he does not become a monster. And if you gaze long enough into an abyss, the abyss will gaze back into you.�
|
|
|
|
|
Joined: Feb 2000
Posts: 49,716
Entil'zha Sierra Hotel
|
|
Entil'zha Sierra Hotel
Joined: Feb 2000
Posts: 49,716 |
And reliability. A glitch can lock you out.
The USAF had retinal scanners at Cape Canaveral back in the 90s I think but they failed so often they dumped them for ID cards you swiped w/PINs.
The Jedi Master
The anteater is wearing the bagel because he's a reindeer princess. -- my 4 yr old daughter
|
|
|
|
|
Joined: Sep 2004
Posts: 5,943
Hotshot
|
|
Hotshot
Joined: Sep 2004
Posts: 5,943 |
Everytime i forget my passwords, i send a msg to NSA or GCHQ. No problem. I ask Matt Wagner.
|
|
|
|
|
Joined: Jan 2011
Posts: 1,527
Member
|
|
Member
Joined: Jan 2011
Posts: 1,527 |
Two step verification (by text) or the use of a password and token would be able to defeat that, I would think....and hope.
Anything is able to defeat this. The article is highly sensationalist. The only particularly new thing here is the speed at which they generated each of the hashes. It a) has nothing to do with password length, a 400 letters long password password would generate the same length in a hash and b) won't work in real life because pretty much 100% of the time NTLM authentication is done with a remote server. Which they of course didn't use, otherwise they wouldn't be able to achieve that speed. What they did here is pretty much the same thing that has been done for ages. Attack the hash/key/you-named that is generated from people's passwords. That's why 64-bit algorithms are not used any more, that's why Microsoft Office's RC-40 was vulnerable, and that's the way encryption algorithms work. All of them. The name of the game is "delay" and not "prevent" breakage.
When you're feeling sad, just remember that somewhere in the world, there's someone pushing a door that says "pull".
|
|
|
|
|
Joined: Jan 2001
Posts: 25,177 Likes: 2
Lifer
|
|
Lifer
Joined: Jan 2001
Posts: 25,177 Likes: 2 |
Yep, that attack requires them to get the password file first. Which is possible, but not so easy.
In any kind of client/server scenario the server will block repeated guesses, deactivate the account etc.
As the article says there are also newer hasl algorythms.
|
|
|
|
|
Joined: Dec 2001
Posts: 2,557
Senior Member
|
|
Senior Member
Joined: Dec 2001
Posts: 2,557 |
The best password to use is "incorrect". This way, if you forget it or type it in wrong, the computer will remind you.
Last edited by jack72; 02/18/16 06:26 PM.
|
|
|
|
|
Joined: Dec 2005
Posts: 1,876
SimHQ's resident fire enthusiast. Member
|
|
SimHQ's resident fire enthusiast. Member
Joined: Dec 2005
Posts: 1,876 |
"When I saw The Matrix at a local theatre in Slovenia, I had the unique opportunity of sitting close to the ideal spectator of the film - namely, to an idiot." - Slavoj Zizek
|
|
|
|
|
|
oselisan
Unregistered
|
|
oselisan
Unregistered
|
The internet is hell for a paranoid like me. I just got into the IT thing a few years ago and really can't keep up or am losing interest in keeping up.
It's like a stupid house. A determined person will find ways to get in. Smashing windows or with lock picks, maybe a freaking battering ram if no one's around. Eh while were at it, throw in some plastic explosives used by SWAT teams to break in.
Right now my stance is to get the basics right. The rest is trying to stay under the radar and not be a target.
|
|
|
|
|
Joined: Jun 2002
Posts: 5,555
Hotshot
|
|
Hotshot
Joined: Jun 2002
Posts: 5,555 |
Notice it is able to crack Windows passwords, not ALL 8 digit passwords. WINDOWS passwords.
Windows is notorious for poor choices regarding encryption and security.
For example, Windows 7 uses MD4 encryption for passwords. This encryption method is SERIOUSLY outdated and was already insecure at the time Windows 7 was introduced. People have been cracking and bypassing them for years.
But one other thing...Windows passwords are useless. All someone needs to do is access your computer with a USB drive with Linux or some other OS on it. They can then see your entire hard drive. The Windows password only stops people from logging in, it does not encrypt your data. It is basically completely useless.
If you are paranoid about security, do an encrypted disk install of Linux and set a long, complicated password generated randomly.
I personally have an encrypted disk Kali Linux installation and I use the Tor browser and Tor network whenever I want to remain anonymous and secure, for example when discussing Japanese politics (JP government has been known to "disappear" people who oppose certain actions it has been conducting recently)
Using the Tor browser with a bridge is pretty much guaranteed security especially if you only use it at random wireless access points, even more so if you uhh...acquire the wireless keys outside of conventional means.
If you are a normal person who's not active in political leaks or you're not handling huge amounts of money, online privacy is not really something you should worry about. Hackers / Russian mob etc. do not care about you. They have higher priority targets. You should worry more about your computer being turned into a zombie for a botnet than worry about whether your name and address are somewhere online.
|
|
|
|
|
|
oselisan
Unregistered
|
|
oselisan
Unregistered
|
Reminded me of the Kali installation I still have on my laptop. Didn't remove it after the contract that required its use was finished.
Hmmm maybe I should take it for a spin just for fun... will need to review some basics.
Yes, I also keep reminding myself that I'm a nobody and hackers etc. have higher priorities. However, with my close relative's emails hacked, including acquaintances (almost everyone around me), I wish I could be 100% sure.
Last edited by oselisan; 02/19/16 11:35 AM.
|
|
|
|
|
Joined: Dec 2014
Posts: 3,552
Senior Member
|
|
Senior Member
Joined: Dec 2014
Posts: 3,552 |
My password is invalid.
So I will never forget it.
|
|
|
|
|
|
|
|
|
|
|
HOA's
by Terl9999 - 09/18/26 04:12 AM
|
Football
by Terl9999 - 09/18/26 02:42 AM
|
Flags
by Terl9999 - 09/15/26 10:03 PM
|
|
|
|
|
|
|
|
|
|