Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Steve Gibson calls this concept the "password haystack". The idea is that the clever hacker will do something like the following:

1) Try known common passwords: "password1", "monkey", etc. 2) Try dictionary words, maybe with leetspeek substitutions, maybe with a single digit on the end 3) Try likely guesses based on what they know about you (if anything) 4) Brute force.

Assuming your password isn't dumb enough for 1-3, you just have to put your needle in a HUGE haystack. If your password is ":$have:$fun:$cracking$:THIS1", brute forcing your password requires trying every combination of upper and lower case, numbers and special characters up to 28 characters.

At one hundred trillion guesses per second, that would take "76.43 million trillion trillion centuries".

Check this out. https://www.grc.com/haystack.htm



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: