Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

Your Password Can Probably be Cracked Faster Than You’d Think

Your Password Can Probably be Cracked Faster Than You’d Think

Whether you’re talking about identity theft, data breaches, or any other form of cybercrime, one of the leading causes of successful cyberattacks is the use of insufficiently secure passwords. Just how easy is it for someone to bypass such a password? Let’s consider the facts.

How to Crack a Password

Cybercriminals come correct, first of all. Not only do many of them have access to some pretty sophisticated tools and resources, they go about their selfish and deceitful activities with a strategy based on the average user’s online conduct.

For the cybercriminal, bypassing a password is really a numbers game. Chances are good that, if they try some commonly used passwords, a cybercriminal will eventually hit pay dirt. For instance, a cybercriminal’s first guesses could look like the following:

  • 123456789
  • guest
  • qwerty
  • password
  • a1b2c3

Since these are some of the world’s most common passwords—with an estimated 10 to 20% of accounts using a similar password—trying different variations of them or adding one or two symbols gives a cybercriminal a pretty good chance of getting in.

If we imagine ourselves to be cybercriminals, this knowledge helps to simplify our process immensely. If we invest in a password cracking tool, which effectively just tries every dictionary word and randomized combination of characters, increasing in length as it goes, chances are good that we will ultimately get in.

It’s just like trying to guess a combination lock number. While it’s going to take some time, you could try every possible combination—1-1-1, 1-1-2, 1-1-3—until you either get it, or the bike’s owner is back and not-so-politely asking you to step away from their property. 

The more variables there are to try, the more possible options there are—increasing at exponential rates, making it impossible to manually try every single combination. A computer, on the other hand, could try…and much, much faster. That’s how a password-cracking tool operates.

How Long Before a Password is Cracked?

It all depends on the password. Many of the tools that these cybercriminals will use will try the usual suspects first, and will therefore crack the password immediately. The shorter, weaker passwords can take fractions of a second, with these tools testing millions of potential credentials in that time.

It also depends on the hardware the cybercriminal is using, as a more powerful system will allow the attacker to test potential passwords that much faster. Let’s go over how speedily a reasonably powerful laptop could crack a password, based on how long the password is, and how complicated it is:

As pictured, weak—or short and simple passwords—would fold immediately, holding out for a few seconds or minutes at best. However, once a password is designed to be longer and more complex, the likelihood of a password being cracked within someone’s lifetime becomes far smaller…arguably impossible.

That is, however, assuming that your password’s length and complexity aren’t wholly reliant on a combination of otherwise common (and therefore, insecure) words or phrases. Sure, “!password12345” may seem to meet some of the basic requirements for a password—and based on the password chart above, should take a million years to figure out—the use of common password trends makes it far easier to figure out.

This is precisely why we always advocate for more stringent password practices to ensure each and every one is sufficiently secure. These practices include the aforementioned length and complexity requirements, and avoiding things that could be guessed somewhat easily, including pet names, birthdays, and other common factors. Of course, passwords should never be used more than once, as in, you need a separate password for each account you’re securing.

It is also important to keep in mind that the results generated above could be accomplished using resources that are out there and available, using a basic tool on a common laptop. An invested cybercriminal very well could have additional resources at their disposal, things like botnets and significant cloud resources, along with the hardware needed to power through a brute force attempt much faster than our hypothetical mid-range laptop could.

The big takeaway: ALWAYS use strong and secure passwords.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Wednesday, 22 January 2025

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud Network Security Internet Hardware User Tips Efficiency IT Support Malware Privacy Email Phishing Google Workplace Tips Computer Collaboration IT Services Users Hosted Solutions Mobile Device Quick Tips Ransomware Cybersecurity Small Business Microsoft Workplace Strategy Data Backup Communication Smartphone Android Passwords Saving Money Business Management VoIP Smartphones Mobile Devices communications Backup Data Recovery Managed Service Upgrade Managed IT Services Social Media Microsoft Office Disaster Recovery Browser Tech Term Network Remote Internet of Things Automation Artificial Intelligence Facebook Cloud Computing Covid-19 Server Remote Work Managed Service Provider Windows Miscellaneous Current Events Gadgets Productivity Holiday Information Outsourced IT Employee/Employer Relationship Encryption Spam AI Windows 10 Government Office Training Data Management Business Continuity Compliance Blockchain Wi-Fi Business Technology Windows 10 Bandwidth Virtualization Two-factor Authentication Mobile Office Data Security Apps Vendor Mobile Device Management Chrome Gmail Budget Managed Services Voice over Internet Protocol Apple Networking App Employer-Employee Relationship BYOD Computing Hacker Information Technology Avoiding Downtime Applications Marketing Access Control Office 365 Tip of the week Conferencing WiFi How To BDR Operating System Computers Virtual Private Network Risk Management HIPAA Router Website Health Office Tips Analytics Augmented Reality Help Desk Retail Storage Password Bring Your Own Device Healthcare Big Data Managed IT Services Windows 7 Remote Monitoring Vulnerability End of Support Customer Service Vendor Management Cybercrime Microsoft 365 Solutions Display Printer Paperless Office Infrastructure Windows 11 IT Support 2FA Monitoring Firewall Document Management Excel The Internet of Things Scam Remote Workers Data loss Telephone Social Going Green Patch Management Cooperation Free Resource Project Management Save Money Settings Images 101 Printing Wireless Mobility Telephone System Multi-Factor Authentication Content Filtering Hacking IT Management Cost Management Presentation VPN YouTube Meetings Physical Security Cryptocurrency Wireless Technology Computer Repair Employees Integration Virtual Desktop Data storage User Tip LiFi Modem Processor Mobile Security Word Holidays Outlook Machine Learning Money Data Storage Smart Technology Supply Chain Humor Video Conferencing Managed Services Provider Virtual Machines Professional Services Safety Saving Time Maintenance Antivirus Sports Mouse Managed IT Service Downloads Administration iPhone Licensing Vulnerabilities Entertainment Data Privacy Robot Customer Relationship Management Star Wars IT Assessment Microsoft Excel IT Maintenance Data Analysis Alt Codes Competition Gamification Flexibility Downtime Unified Threat Management Staff Value Business Intelligence Legislation Shortcuts Unified Threat Management Organization Hosted Solution Social Networking Typing Smart Devices Ransmoware Fileless Malware Digital Security Cameras Content Remote Working Wearable Technology Memory Vendors Network Congestion Knowledge Comparison Google Play Be Proactive Google Drive User Error Health IT User Motherboard Data Breach Assessment Electronic Health Records Permissions Workforce Directions Videos Point of Sale Wasting Time Threats 5G Experience Specifications Security Cameras Workplace Strategies IP Address Google Docs Unified Communications Trend Micro Bitcoin Network Management Internet Exlporer Software as a Service Running Cable Tech Support Fraud Meta Microchip Google Wallet Username Managing Costs Amazon Monitors Black Friday SSID Recovery eCommerce Hard Drives Windows 8 Database Surveillance Laptop Websites Virtual Assistant Outsource IT Domains Drones IT Technicians Virtual Machine Environment Media Cookies Electronic Medical Records Cyber Monday Medical IT SharePoint Proxy Server Reviews Refrigeration Tactics Development Halloween Hotspot Transportation Small Businesses Public Speaking Lenovo Mirgation Hypervisor Displays Writing Nanotechnology Optimization Virtual Reality PowerPoint Lithium-ion battery Shopping Hacks Server Management Addiction Entrepreneur Scary Stories Private Cloud Language Employer/Employee Relationships Outsourcing Navigation Superfish Management PCI DSS Identity Theft Chatbots Fun Screen Reader Twitter Distributed Denial of Service Workplace Gig Economy Deep Learning Undo Service Level Agreement Internet Service Provider Error Computing Infrastructure Teamwork Hiring/Firing Evernote Paperless Regulations Compliance Education Identity Social Engineering Smart Tech Memes Remote Computing Co-managed IT Bookmark Mobile Computing Download Net Neutrality Alerts SQL Server Technology Care Business Communications Financial Data Tablet History Search Connectivity IT Alert Break Fix Scams Browsers Smartwatch Application Best Practice Managed IT Upload Procurement Buisness File Sharing Azure Hybrid Work Dark Data Multi-Factor Security Tech Human Resources IBM Legal Social Network Telework IT solutions Cyber security How To IoT Communitications Notifications Dark Web Cables CES Business Growth Trends Supply Chain Management Travel Google Calendar Term Google Apps Techology Customer Resource management FinTech Google Maps Regulations Cortana

Blog Archive