Pages: [1]   Go Down
  Print  
Author Topic: GPU cracks password in 4 seconds  (Read 166 times)
0 Members and 1 Guest are viewing this topic.
Hijpo
Business Class
From a glass
****

Good Guy/Gal Points. 34
Online Online

Posts: 675



« on: October 08, 2011, 10:39:27 PM »

http://thehackernews.com/2011/10/gpu-cracks-6-character-password-in-4.html?utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+TheHackersNews+%28The+Hackers+News+-+Daily+Cyber+News+Updates%29&m=1

Thas nuts
Logged

Wooster
Wall Eyed Wanker
Administrator
Alcoholic
*

Good Guy/Gal Points. -518
Offline Offline

Posts: 5550


'An how faust kin it ging?'


« Reply #1 on: October 08, 2011, 10:55:49 PM »

Aye, they've been doing that for a while now with quad setups and such, but 4 seconds on an old card ain't bad. Cool


...then again, maybe it is bad...for us all. scratchhead
Logged

Hijpo
Business Class
From a glass
****

Good Guy/Gal Points. 34
Online Online

Posts: 675



« Reply #2 on: October 08, 2011, 11:23:26 PM »

It doesnt say what method it used to crack them or what kind of password it was, random characters or dictionary words  confused
Logged

corroded
Humbug Monkee
Pub regular
*******

Good Guy/Gal Points. 73
Offline Offline

Posts: 3916


Shop Smart, Shop S-Mart.


« Reply #3 on: October 10, 2011, 08:17:05 PM »

Yeah it does, it says 6 character strong passwords, which implies alpha numeric, punctuation and capitalisation.

It's not quite that simple. That'd simply be a hashed password, with no salting, probably some md5 or sha1 based hash. It'll be decent at cracking people who don't know how to set up any security (and probably exposing password upon password to another site, as people always use the same combination). Salting adding in that unknown factor adds a large factor of randomness to the hash..

I'm personally thinking of switching my passwords over to a system based on Diceware
« Last Edit: October 10, 2011, 08:21:13 PM by corroded » Logged
Wooster
Wall Eyed Wanker
Administrator
Alcoholic
*

Good Guy/Gal Points. -518
Offline Offline

Posts: 5550


'An how faust kin it ging?'


« Reply #4 on: October 10, 2011, 10:01:48 PM »

I had reason to bitch about some password policies recently.

It's a client site that requires a Username/PIN + RSA/Password.

Problem is, they request a monthly change on the Password, but it's a portal to a Telnet app I use (Citrix) that also requires a monthly change of password.. and they use different criteria when it comes to stuff like Caps/Non caps/Letters + Numbers etc.
Not only that, they have another site I use that has an entirely different set of criteria for logging in, and the password change request can occur monthly, quarterly or bi-annually.

My point was that making it so awkward, forces people to write things down.

.It isn't going to make any difference though, since their Admins will be following the standard Windows Server xxxx methodology, so it's going to be like it always was.
...turn over the keyboard, look in the top drawer...and somewhere, among the clutter, will be a bit of paper with all the details you need to know.  Wink
« Last Edit: October 10, 2011, 10:03:15 PM by Wooster » Logged

corroded
Humbug Monkee
Pub regular
*******

Good Guy/Gal Points. 73
Offline Offline

Posts: 3916


Shop Smart, Shop S-Mart.


« Reply #5 on: October 11, 2011, 12:50:51 AM »

I only have two passwords... one that leads to a drive, and one that leads to many others. And that is a fifteen digit long alpha numeric, punctuated beast that I've memorised.
Logged
Hijpo
Business Class
From a glass
****

Good Guy/Gal Points. 34
Online Online

Posts: 675



« Reply #6 on: October 11, 2011, 08:13:02 AM »

What about ASCII symbols? Can they be used?
Logged

corroded
Humbug Monkee
Pub regular
*******

Good Guy/Gal Points. 73
Offline Offline

Posts: 3916


Shop Smart, Shop S-Mart.


« Reply #7 on: October 11, 2011, 03:36:47 PM »

They can be... depends on the system supporting it I guess. Still not as good as a Diceware list though.

http://en.wikipedia.org/wiki/Password_strength
Logged
Pages: [1]   Go Up
  Print  
 
Jump to: