DATA DOCTORS

If I get locked out after trying my password too many times, how do hackers get in?

Jan 31, 2016, 8:26 AM

(AP Photo/Kin Cheung, File)...

(AP Photo/Kin Cheung, File)

(AP Photo/Kin Cheung, File)

Q: If I get locked out of my account when I type three wrong passwords, how are hackers able to use guessing to break in?

Hackers and security experts are in a constant chess match that never ends: Each move by one party causes the other party to take a new approach.

A couple of commonly-used approaches by hackers to break passwords are often referred to as dictionary and/or brute force attacks. They’re essentially computer programs that can generate millions, if not hundreds of millions of guesses per second.

The notion that hackers sit at a computer using the same login screens we all use to try to access our accounts is the first one we need to correct.

Often times, they are using an offline attack combined with automation and breached data to break passwords on specific sites. Since the attack is offline — meaning they have acquired enough cryptographic information to attempt to break passwords — they aren’t subject to the password lockout protection.

It gets a bit complicated, but they can just set their computers to compare the specially-encoded information against known passwords in what are called “rainbow tables,” which allows them to find matches.

The lack of understanding of how hackers actually hack passwords and the false sense of security caused by account lockout mechanisms leads to complacency by so many users.

According to the Privacy Rights Clearinghouse, there have been 895,605,985 records breached from 4,746 data breaches since 2005. Keep in mind, this number only represents the data breaches that have been made public.

Every data breach that exposes user passwords allows the hacking community to continue to compile huge rainbow tables, so even if you haven’t used a password before, if it’s too common, you’re an easy target.

If the general non-hacking public can get its hands on the top 10,000 most commonly used passwords in 30 seconds on Google, how many passwords do you think professional cyber-thieves have compiled?

This is why using the same password for multiple online accounts can easily make you a victim, especially at sites that use your e-mail address as your username.

Complex eight-character passwords are nearly useless in today’s environment. Creating long pass phrases instead is a better way to reduce your chances of being victimized by the powerful hacker guessing game.

For example, “I Hate Passw0rds!” is much more secure than A8y@q7P1 and much easier to remember.

The longer the password, the less likely it can be broken via the high-speed guessing game, so shoot for at least 15 characters.

You should also assume that your passwords will be compromised by a data breach at some point, so activating two-factor authentication on your accounts will help keep the bad guys out, even if they do get your passwords!

Data Doctors

Patrick Mahomes #15 and head coach Andy Reid of the Kansas City Chiefs are recorded on a phone as t...

Data Doctors

Handy tech tips all Valley residents should use to find lost phones in a snap

Q: My phone went missing, and I haven’t been able to locate it using the Find My service, so what should I do next?

5 days ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are tips for freeing up Google storage space

Google provides a generous amount of free online storage but it can fill up quickly depending on how many of its resources you use.

12 days ago

Discover how to assess, estimate, and shop for the right battery pack with this concise guide. (Pex...

Data Doctors

Here is everything you need to know for testing and buying battery banks

Discover how to assess, estimate and shop for the right battery pack with this concise guide.

19 days ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are the truly free smartphone video editing apps

The processing power on our smartphones has grown exponentially, allowing anyone to perform sophisticated video editing easily.

26 days ago

Google Maps app....

Data Doctors

How to rediscover places visited years ago on Google maps

Whether you're an Android or iOS user, or prefer accessing Google Maps on your computer, you'll find step-by-step instructions to unlock your travel memories effortlessly.

1 month ago

(Photo by Michael Bocchieri/Getty Images)...

Ken Colburn, Data Doctors

Here’s how to calculate your bandwidth needs

When searching for an alternative internet service provider, here are some tips on how to know how much bandwidth is needed.

1 month ago

Sponsored Articles

...

Midwestern University

Midwestern University Clinics: transforming health care in the valley

Midwestern University, long a fixture of comprehensive health care education in the West Valley, is also a recognized leader in community health care.

...

Fiesta Bowl Foundation

The 51st annual Vrbo Fiesta Bowl Parade is excitingly upon us

The 51st annual Vrbo Fiesta Bowl Parade presented by Lerner & Rowe is upon us! The attraction honors Arizona and the history of the game.

...

Collins Comfort Masters

Avoid a potential emergency and get your home’s heating and furnace safety checked

With the weather getting colder throughout the Valley, the best time to make sure your heating is all up to date is now. 

If I get locked out after trying my password too many times, how do hackers get in?