Password cracking is getting ridiculous

TECHi's Author
Opposing Author Arstechnica Read Source Article
Last Updated
TECHi's Take
Carl Durrek
Carl Durrek
  • Words 37
  • Estimated Read 1 min

Your password is not really that secure. Unless you have a 22-character randomized password (that won’t even work in many password sections on websites) your passwords such as “thisisnotyourpassword123” might seem secure, but it’s not.

Arstechnica

Arstechnica

  • Words 147
  • Estimated Read 1 min
Read Article

Early last year, password security researcher Kevin Young was hitting a brick wall. Over the previous few weeks, he made steady progress decoding cryptographically protected password data leaked from the then-recent hack of intelligence firm Stratfor. But with about 60 percent of the more than 860,000 password hashes cracked, his attempts to decipher the remaining 40 percent were failing.

The so-called dictionary attacks he mounted using lists of more than 20 million passwords culled from previous website hacks had worked well. Augmented with programming rules that substituted letters for numbers or combined two or more words in his lists, his attacks revealed Stratfor passwords such as “pinkyandthebrain,” “pithecanthropus,” and “moonlightshadow.” Brute-force techniques trying every possible combination of letters, numbers, and special characters had also succeeded at cracking all passwords of eight or fewer characters. So the remaining 344,000 passwords, Young concluded, must be longer words or phrases few crackers had seen before.

Source

NOTE: TECHi Two-Takes are the stories we have chosen from the web along with a little bit of our opinion in a paragraph. Please check the original story in the Source Button below.

Balanced Perspective

TECHi weighs both sides before reaching a conclusion.

TECHi’s editorial take above outlines the reasoning that supports this position.

More Two Takes from Arstechnica

Apple won’t be announcing its television service next week after all
Apple won’t be announcing its television service next week after all

Those of you who have been anticipating the announcement of Apple's long-rumored subscription television service should prepare yourselves for disappointment.…

Kyocera is being sued by Microsoft for infringing on Android patents
Kyocera is being sued by Microsoft for infringing on Android patents

Despite being a direct competitor in the mobile market, Microsoft actually owns quite a few Android patents and isn't afraid…

Maybe default encryption for Android wasn’t such a good idea
Maybe default encryption for Android wasn’t such a good idea

While Android has supported disk encryption for a while now, Android 5.0 is the only version that implements it by…

The FCC has approved America’s strongest-ever net neutrality rules
The FCC has approved America’s strongest-ever net neutrality rules

The strongest net neutrality rules that the United States has ever seen were approved by the FCC in a highly-anticipated…