Password test

Status
Not open for further replies.
Joined
Jan 13, 2016
Messages
3,488
Location
Northeast Nebraska
I'm sure some of you have seen this site or similar but for you that don't think strong passwords are necessary try your password here and it will tell you how long it would take to crack it.

https://howsecureismypassword.net/

At work I deal with a lot of passwords for out customers. Websites, blogs. email etc.... I like to send this link out to them for fun.
 
Sounds about as legit as when Peggy from the IRS calls and asks for your social security number over the phone.
 
One of mine was 25 microseconds......haha

I only use it for a couple forums. So if all of a sudden, Im am posting adds for sunglasses at 98% off, you know I got hacked......lol
 
Originally Posted By: 2015_PSD
LOL - I think I am covered:




It will take far less than that amount of time for Quantum computers to be properly developed. Once that happens, all bets are off.
 
Originally Posted By: SirTanon
Originally Posted By: 2015_PSD
LOL - I think I am covered:

It will take far less than that amount of time for Quantum computers to be properly developed. Once that happens, all bets are off.
Perhaps, but since I change them on a regular basis, short of a keylogger coming into play, I will be long gone before I need to be concerned about it.
 
Originally Posted By: 2015_PSD
Originally Posted By: SirTanon
Originally Posted By: 2015_PSD
LOL - I think I am covered:

It will take far less than that amount of time for Quantum computers to be properly developed. Once that happens, all bets are off.
Perhaps, but since I change them on a regular basis, short of a keylogger coming into play, I will be long gone before I need to be concerned about it.


I just made a representative password since all my important passwords are converting to random 16 digit sets and being stored. I'm not putting my last pass master password in lol

41 trillion years.


Edit: I just put in a representative password with the same method that my master password is comprised of: 400 years
That's good enough for me.
 
Last edited:
In general those password rating sites are not all that accurate. I've tried making strong-ish passwords that are rated as taking over a year to crack. However once I hash the password out and put it into hashcat I can break most "strong" passwords with a dictionary attack in less then 10 mins.

Brute force is the only way one some passwords (granted I'm not suggesting or even condoning "hacking"). A few of my friends like to challenge each other and we will hash a password out and see who can break it the quickest.

Anyways I'm going off topic. Some passwords will require brute force and depending on the length it can take a few hours to a few days depending on that hashing algorithm they use (md5, sha1, or bcrypt (years lol).

Don't take sites like this to seriously they are mostly meant for you to feel good and secure. If a less then reputable site owner releases one of these sites they could simply be hashing out every password you enter then adding it to their dictionary so you never know.
 
Last edited:
One representative of the sort of passwords I use said it would take 400 years for a computer to crack.

I'm not willing to give an actual password, but made up one using the same scheme....
 
I apologize, I really didn't think anyone would take this seriously, thats why I said I send it out for fun.

Let me explain, I get customer calling in all the time that forget their passwords and want to use something they can remember which is always to easy, like their dogs name followed by the year they were born. So after I setup a good password for them I email some of them this link and tell them to put in what ever it was they wanted to use so they can see how fast it could be cracked.
 
Last edited:
Originally Posted By: Duffyjr
I apologize, I really didn't think anyone would take this seriously, thats why I said I send it out for fun.
It is fun:

For example, this result:



Comes from this password:

H0w$&CuR&!$mYP@$$w0rD?2017
 
In the upcoming version they will have you enter your bank account number, your SSN and your password along with your name and address to rate how secure your password might be. It's amazing what you can get for free in the Internet.
 
Originally Posted By: Duffyjr
I apologize, I really didn't think anyone would take this seriously, thats why I said I send it out for fun.

Let me explain, I get customer calling in all the time that forget their passwords and want to use something they can remember which is always to easy, like their dogs name followed by the year they were born. So after I setup a good password for them I email some of them this link and tell them to put in what ever it was they wanted to use so they can see how fast it could be cracked.



Nah, I completely understand. I should have worded my comment better I suppose. Nothing wrong with the thought at all and I understand where you are coming from. I just wanted to mention in general just because a site says a password is super secure does not mean it is. These sites typically just look at total length of the pass and if any numbers, uppercase, lowercase, or special characters where used.

There is a hand full of security company's that strip all the illegal content out of data base breaches (mainly just keeping the password/hash. They run these over a A.I. system to determine how people create passwords and the patterns in between.

You can build rulesets with the finding to manipulate the dictionaries to improve their odds.

Most passwords are 8-10 characters in length followed up with a capital letter at the start with lowercase until the last 1-4 characters either being (as you said a birth year or any form of year most commonly being the year they created the password.

Password complexity only helps with dictionary attacks and even then its not super effective. At this time length wins but even then length can be beat by brute force depending on the hashing algorithm. I use a 980ti and in most cases I'm able to guess 18.6 billion hashes a second.

Anyways I've gone off track again.
 
Status
Not open for further replies.
Back
Top