DATA DOCTORS

Here’s how hackers are able to crack your passwords

Feb 27, 2021, 7:15 AM

(Photo by Tomohiro Ohsumi/Getty Images)...

(Photo by Tomohiro Ohsumi/Getty Images)

(Photo by Tomohiro Ohsumi/Getty Images)

Q: How can hackers try millions of passwords at a time when I will get locked out after 3 failed attempts?

A: Passwords continue to be the primary target of cybercriminals because they represent the “keys to your kingdom,” especially when it comes to your email account.

Online security tools such as Gibson Research’s Haystack tool show you just how quickly any short password can be cracked, but it’s based on billions and trillions of guesses per second.

Tools like this are showing how fast a ‘brute force’ attack can break shorter passwords, which typically will occur offline.

Offline Password Cracking

Your question is a common one because most people assume that password hacking is done through the same interface as we all use to log into our accounts, but that’s not the typical approach.

All of the websites that require you to enter a password store those passwords using some form of what’s known as ‘hashing’. This means that your password is converted into a random string of characters that looks nothing like your actual password before it gets stored on their servers.

As an example, the common password “monkey” in MD5 Hashing will always be stored as “d0763edaa9d9bd2a9516280e9044d885” which is child’s play for a computer to convert back to the original word.

Most offline cracking activity begins after a breach has occurred and the database of ‘hashed’ passwords are stolen and saved elsewhere to be worked on.

Think of it as a bank robber stealing the vault and cracking it somewhere else vs. trying to crack open the vault at the bank itself.

Brute force attacks are essentially a guessing game that pits computing power against the length of your password, which is why creating a longer password is always better.

It’s simple math as every combination of letters, numbers and special characters can be tried in milliseconds if there is enough computing power available.

In the Haystack tool, you will see that any 8-character password can be broken in just over 1 minute.

As you add additional characters, the time to crack them goes up because each additional character exponentially increases the number of guesses required.

Given enough time, all passwords can be cracked, so what you want to do is create long enough passwords that aren’t worth the time to crack.

Other Password Hacking Techniques

Brute Force is just one of many methods hackers use to crack passwords, which is why it’s so important to use a different long password for each of your online accounts.

There are ‘Dictionary attacks’, which use every word and any combination of those words that can be found in a dictionary.

‘Rainbow Table attacks’ use a form of known password databases because they’ve pre-computed all of the possible password combinations for all of the most common hashing techniques in one big table. This greatly reduces the time it takes to crack a password because it becomes a simple lookup exercise.

Although these attacks have been around since the beginning, sophisticated phishing and social engineering schemes are a faster way to get real passwords that can be exploited, which is why they continue to grow and evolve.

Data Doctors

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are the best tips for mobile file sharing

Airdrop is Apple’s proprietary method to exchange files between Apple devices and can’t be used to send files directly to Android devices, but there are other options.

4 days ago

(Unsplash Photo)...

Data Doctors

Random caller? Here are tips for looking up unfamiliar phone numbers

If you've ever wondered who's calling you, then here are some tips for looking up unfamiliar phone numbers.

11 days ago

...

Data Doctors

5 tips to speed up Google’s Chrome browser if it has begun to lag

The plethora of extensions available for Google Chrome can be one of many reasons why a users' browsing experience can be noticeably slower.

18 days ago

(StockSnap.io Photo)...

Data Doctors

When a computer freezes up, solutions can vary from bypassing cache to OS updates

When a computer freezes, the reality is it’s a sign that you have a significant issue that needs to be addressed.

25 days ago

Windows 11 and Windows 10 operating system logos are displayed on laptop screens for illustration p...

Data Doctors

Tips for knowing how and when to upgrade to Windows 11

Windows 10 isn’t being discontinued; it’s coming up to its ‘End Of Life’ in Microsoft’s support lifecycle.

1 month ago

(Photo by Pierre Crom/Getty Images)...

Ken Colburn, Data Doctors

Here’s what you need to know about using smartphone mobile payment systems

There are good reasons to consider using the mobile payment systems that most smartphones support, ranging from convenience to security.

1 month ago

Sponsored Articles

...

DAY & NIGHT AIR CONDITIONING, HEATING AND PLUMBING

Here are the biggest tips to keep your AC bill low this summer

PHOENIX — In Arizona during the summer, having a working air conditioning unit is not just a pleasure, but a necessity. No one wants to walk from their sweltering car just to continue to be hot in their home. As the triple digits hit around the Valley and are here to stay, your AC bill […]

...

Desert Institute for Spine Care

Spinal fusion surgery has come a long way, despite misconceptions

As Dr. Justin Field of the Desert Institute for Spine Care explained, “we've come a long way over the last couple of decades.”

(Photo by Michael Matthey/picture alliance via Getty Images)...

Cox Communications

Valley Boys & Girls Club uses esports to help kids make healthy choices

KTAR’s Community Spotlight focuses on the Boys & Girls Club of the Valley and the work to incorporate esports into children's lives.

Here’s how hackers are able to crack your passwords