[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: How to choose a good password



In article <53gktg$3b6@seeker.the-hermes.net>,
Geoff Weiss <geoff@the-hermes.net> wrote:
>For example, a password which can't be broken by such cracking programs
>would be: h6F>9ukr.  The only way this could be cracked is if this password
>is stored in a database of previously used passwords.  Well, it is not true
>that the password is "unbreakable."  If you had a Cray, you could probably
>crack the password in couple hundred thousand years.  The odds are too great
>for the password to be broken.

   Way less than that. It's been calculated that for $10 million
dollars, you can buy a computer that'll crack it by brute force in <30
seconds.  $1 mil, 300 seconds. A password is only 8 characters, and
maybe 110 possibilities per character (stuff like return (^M), delete
and others can't be included). Only 2*10^16 possibilities. You can bet
that the NSA and probably some other groups have one of these password
crackers, or they just run it in the spare time on a cray around the
country.

Nathan Mates
--
<*> Nathan Mates http://www.visi.com/~nathan/      <*>
# What are the facts? Again and again and again-- what are the _facts_?
# Shun wishful thinking, avoid opinion, care not what the neighbors
# think-- what are the facts, and to how many decimal places?  -R.A. Heinlein