# Password Recovery Speeds

**URL:** <https://forum.kirupa.com/t/password-recovery-speeds/184351>\
**Category:** random\
**Created:** [April 4, 2006, 3:36pm UTC](https://forum.kirupa.com/t/password-recovery-speeds/184351 "2006-04-04T15:36:08Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![kritikal](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/kritikal/32/1699_2.png) [@kritikal](https://forum.kirupa.com/u/kritikal)\
**Post date:** [April 4, 2006, 3:36pm UTC](https://forum.kirupa.com/t/password-recovery-speeds/184351/1 "2006-04-04T15:36:08Z")

</div>

Have you ever wondered how long it would take to crack your password?

[http://www.lockdown.co.uk/?pg=combi&s=articles](http://www.lockdown.co.uk/?pg=combi&s=articles)

apparently mine would be cracked in 8 and a half hours on a slow pc and instantly on a supercomputer 😑

---

<div class="post-metadata">

**Author:** ![bwh2](https://avatars.discourse-cdn.com/v4/letter/b/8c91f0/32.png) [@bwh2](https://forum.kirupa.com/u/bwh2)\
**Post date:** [April 4, 2006, 3:42pm UTC](https://forum.kirupa.com/t/password-recovery-speeds/184351/2 "2006-04-04T15:42:25Z")

</div>

yeah, and those are brute force attacks, which most are not. most work off of dictionaries which drastically reduce the time. i think at work one day we cracked about 10,000 password protected files in 4 minutes. good stuff.

---

<div class="post-metadata">

**Author:** ![Seb\_Hughes](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@Seb\_Hughes](https://forum.kirupa.com/u/Seb_Hughes)\
**Post date:** [April 4, 2006, 3:48pm UTC](https://forum.kirupa.com/t/password-recovery-speeds/184351/3 "2006-04-04T15:48:47Z")

</div>

Mine would take ages.

8 7.2 Quadrillion 22,875 Years 2,287 Years 229 Years 23 Years 2¼ Years 83½ Days

Mine has more characters.

---

<div class="post-metadata">

**Author:** ![Jeff\_Wheeler](https://avatars.discourse-cdn.com/v4/letter/j/59ef9b/32.png) [@Jeff\_Wheeler](https://forum.kirupa.com/u/Jeff_Wheeler)\
**Post date:** [April 16, 2006, 7:57pm UTC](https://forum.kirupa.com/t/password-recovery-speeds/184351/4 "2006-04-16T19:57:05Z")

</div>

So… basically you’d never figure out my site password… not with a dictionary, not with brute force. 🙂

---

<div class="post-metadata">

**Author:** ![evildrummer](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/evildrummer/32/2308_2.png) [@evildrummer](https://forum.kirupa.com/u/evildrummer)\
**Post date:** [April 16, 2006, 9:36pm UTC](https://forum.kirupa.com/t/password-recovery-speeds/184351/5 "2006-04-16T21:36:19Z")

</div>

well my password is 16 characters using upper lower case numerals and common symbols, so if 8 is 7.2 Quadrillion 22,875 Years 2,287 Years 229 Years 23 Years 2¼ Years 83½ Days  
and mine is 14, thats alot of years on class A

---

<div class="post-metadata">

**Author:** ![krilnon](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/krilnon/32/34_2.png) [@krilnon](https://forum.kirupa.com/u/krilnon)\
**Post date:** [April 16, 2006, 9:51pm UTC](https://forum.kirupa.com/t/password-recovery-speeds/184351/6 "2006-04-16T21:51:28Z")

</div>

It would take much longer if you were attempting to log into the control panel for a server over the internet, there’s no way that the server would accept (or be able to handle) such a large number of attempts in such a short time.

---

<div class="post-metadata">

**Author:** ![bwh2](https://avatars.discourse-cdn.com/v4/letter/b/8c91f0/32.png) [@bwh2](https://forum.kirupa.com/u/bwh2)\
**Post date:** [April 17, 2006, 11:22pm UTC](https://forum.kirupa.com/t/password-recovery-speeds/184351/7 "2006-04-17T23:22:41Z")

</div>

that’s why you’d drop a utility on the server so that it’s local to that machine.

---

<div class="post-metadata">

**Author:** ![JoshuaJonah](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/joshuajonah/32/1775_2.png) [@JoshuaJonah](https://forum.kirupa.com/u/JoshuaJonah)\
**Post date:** [April 17, 2006, 11:26pm UTC](https://forum.kirupa.com/t/password-recovery-speeds/184351/8 "2006-04-17T23:26:32Z")

</div>

lol… hack much?

---

<div class="post-metadata">

**Author:** ![bwh2](https://avatars.discourse-cdn.com/v4/letter/b/8c91f0/32.png) [@bwh2](https://forum.kirupa.com/u/bwh2)\
**Post date:** [April 18, 2006, 12:26am UTC](https://forum.kirupa.com/t/password-recovery-speeds/184351/9 "2006-04-18T00:26:04Z")

</div>

nah, never got into that stuff. just makes common sense that i/o is the bottleneck.

---

<div class="post-metadata">

**Author:** ![krilnon](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/krilnon/32/34_2.png) [@krilnon](https://forum.kirupa.com/u/krilnon)\
**Post date:** [April 18, 2006, 10:51am UTC](https://forum.kirupa.com/t/password-recovery-speeds/184351/10 "2006-04-18T10:51:23Z")

</div>

> [@bwh2](#):
>
> that’s why you’d drop a utility on the server so that it’s local to that machine.

It seems like that would be rather hard to do if it was a well-protected server.

---

<div class="post-metadata">

**Author:** ![bwh2](https://avatars.discourse-cdn.com/v4/letter/b/8c91f0/32.png) [@bwh2](https://forum.kirupa.com/u/bwh2)\
**Post date:** [April 18, 2006, 6:57pm UTC](https://forum.kirupa.com/t/password-recovery-speeds/184351/11 "2006-04-18T18:57:39Z")

</div>

> [@Krilnon](#):
>
> It seems like that would be rather hard to do if it was a well-protected server.

there are a lot of things that would seem difficult to get into, but that’s because people overlook the obvious. for instance, a buddy of mine at work basically did legal system break-ins for a few years (basically his company was hired by clients to try to hack into their networks). so yeah, they would try a lot of technical stuff, but then they would do really simple stuff that’s easily overlooked - like calling someone (non-IT) and say you’re so and so from IT and you just need their username and password to (insert something technical to confuse the person). so they would get a username and password over the phone and like that, they’re on the network.

you have to remember that not everyone with server access is techical, not even close.

---

<div class="post-metadata">

**Author:** ![Jeff\_Wheeler](https://avatars.discourse-cdn.com/v4/letter/j/59ef9b/32.png) [@Jeff\_Wheeler](https://forum.kirupa.com/u/Jeff_Wheeler)\
**Post date:** [April 18, 2006, 9:44pm UTC](https://forum.kirupa.com/t/password-recovery-speeds/184351/12 "2006-04-18T21:44:15Z")

</div>

Heh… :lol:

That’s great!

---

<div class="post-metadata">

**Author:** ![abreev8](https://avatars.discourse-cdn.com/v4/letter/a/90ced4/32.png) [@abreev8](https://forum.kirupa.com/u/abreev8)\
**Post date:** [April 18, 2006, 10:35pm UTC](https://forum.kirupa.com/t/password-recovery-speeds/184351/13 "2006-04-18T22:35:56Z")

</div>

My pw is so secure, they don’t even list it on there 😛 I use different passwords for everything I use varying from 12 to 16 characters.

So given it takes a super PC more than 8 days for 8 characters (provided you make use of a random selection from the 96) and it’s exponential, it would take forever to crack mine by brute force. That’s reassuring.

The only problem is, I keep running into websites that have stupid limits on their passwords. Like I can’t use most any symbol characters in some places. Like the wells fargo website!!! If any of my passwords needs to be secure, it’s that one, but I have to make it less safe for them 😱

---

<div class="post-metadata">

**Author:** ![3d\_Nirvana](https://avatars.discourse-cdn.com/v4/letter/3/a88e4f/32.png) [@3d\_Nirvana](https://forum.kirupa.com/u/3d_Nirvana)\
**Post date:** [April 19, 2006, 3:23am UTC](https://forum.kirupa.com/t/password-recovery-speeds/184351/14 "2006-04-19T03:23:47Z")

</div>

> [@bwh2](#):
>
> there are a lot of things that would seem difficult to get into, but that’s because people overlook the obvious. for instance, a buddy of mine at work basically did legal system break-ins for a few years (basically his company was hired by clients to try to hack into their networks). so yeah, they would try a lot of technical stuff, but then they would do really simple stuff that’s easily overlooked - like calling someone (non-IT) and say you’re so and so from IT and you just need their username and password to (insert something technical to confuse the person). so they would get a username and password over the phone and like that, they’re on the network.
> 
> you have to remember that not everyone with server access is techical, not even close.

lol on a slightly related note… i was kinda freaked out when I went to the sprint store, cancelled a service and added something to my phone plan and all they asked me for is my name. lol

---

<div class="post-metadata">

**Author:** ![bwh2](https://avatars.discourse-cdn.com/v4/letter/b/8c91f0/32.png) [@bwh2](https://forum.kirupa.com/u/bwh2)\
**Post date:** [April 21, 2006, 4:11am UTC](https://forum.kirupa.com/t/password-recovery-speeds/184351/15 "2006-04-21T04:11:49Z")

</div>

it should also be noted that these speeds are referring to system passwords, not embedded file passwords. so if you have let’s say an excel file with a built in password, that’s really easy to crack, even if it’s some long combination of numbers and letters (caps and non).

basically a password cracker will identify where the password exists in the hex by guessing it repeatedly. then based on the changes in the file’s md5 (or sha1) the cracker will get closer to the password until it finally hits it. so i wouldn’t advise using the same password for let’s say an office document as for a bank account. files with embedded passwords aren’t secure at all.
