Announcement

Collapse
No announcement yet.

Latest ATT honeypot data reveals the top password as:

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    #16
    I've often wondered about the differences in passwords -- all lower case, mixed case, lower case and numerics, mix case and numerics, all the previous and with special characters, just special characters, etc....

    The thing is, they are all coming from a pool of 256 bytes. The alpha numerics between 0 and 127, and the higher set from 128 to 256. Does it really matter which combination of ANY of those characters (0-256) are used? In my mind, only one thing makes any difference -- length of the password. Some apps and sites limit the length of the password, or truncate it to some fixed upper number, so even the length of the password is defeated.

    My passwords are phrases of three or four words, sometimes with numbers or punctuation, averaging 16 characters. Always longer, but easy to remember. I read that even 4096 bit RSA keys have been cracked using a "side channel attack". Besides the acoustic attack on the 4096 bit key, the 1024 bit RSA key was cracked in 2010. My PGP keys are either 2048 or 4096.

    However, considering the resources behind the NSA, including $80M targeted to build a quantum computer that could crack most if not all key, one wonders if they have that already.

    Google has purchased a D-Wave Systems quantum computer, so I am not sure why NSA is trying to build one, and suspect that their announcement is merely a smoke screen.
    "A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
    – John F. Kennedy, February 26, 1962.

    Comment


      #17
      How Big is Your Haystack?
      ... and how well hidden is YOUR needle?
      Windows no longer obstructs my view.
      Using Kubuntu Linux since March 23, 2007.
      "It is a capital mistake to theorize before one has data." - Sherlock Holmes

      Comment


        #18
        That's a useful link Snowhog, thanks!

        samhobbs.co.uk

        Comment


          #19
          I got a 95

          Search Space Depth (Alphabet): XX+XX+XX+XX = 95

          Please Read Me

          Comment


            #20
            Mine:

            Brute Force Search Space Analysis:
            Search Space Depth (Alphabet): 26+26+10+33 = 95
            Search Space Length (Characters): 16 characters
            Exact Search Space Size (Count):
            (count of all possible passwords
            with this alphabet size and up
            to this password's length)
            44,480,886,725,444,
            405,624,219,204,517,120
            Search Space Size (as a power of 10): 4.45 x 1031


            Time Required to Exhaustively Search this Password's Space:
            Online Attack Scenario:
            (Assuming one thousand guesses per second)
            14.14 million trillion centuries
            Offline Fast Attack Scenario:
            (Assuming one hundred billion guesses per second)
            1.41 hundred billion centuries
            Massive Cracking Array Scenario:
            (Assuming one hundred trillion guesses per second)
            1.41 hundred million centuries
            Windows no longer obstructs my view.
            Using Kubuntu Linux since March 23, 2007.
            "It is a capital mistake to theorize before one has data." - Sherlock Holmes

            Comment

            Working...
            X