Hi All
With just a few dollars, a little time, and a smart brute-force guessing algorithm, most passwords can be cracked in much less time than you might imagine. According to a new analysis from the experts at Kaspersky, 59% of 193 million actual passwords were cracked in less than 60 minutes, and 45% were cracked in less than 60 seconds.
The basis of a brute-force attack is where the perpetrator iterates all possible combinations in order to find a match for the password in question. However, Antonov explained, “smart guessing algorithms are trained on a passwords data-set to calculate the frequency of various character combinations and make selections first from the most common combinations and down to the rarest ones.”
Regards
Caute_Cautim
There's some movement in industry towards passwordless authentication. But phishing resistant MFA Is also recommended even if passwords do need to be used. (Awareness efforts like World Password Day have helped us spread good information, though.) Unfortunately, sometimes there are programmatic (SW) and/or hardware programmed limitations regarding password complexity.
Lee Kim
ISC2 Board Candidate 2024