The Average American's Password Could Be Hacked in Under One Hour

numike

Level 1
Thread author
Verified
Nov 1, 2018
48
A recent study conducted by security firm Hive Systems found that passwords below ten characters in length could often end up hacked in under an hour (and this length of time is shrinking as computer hardware processing power improves).

According to their study, passwords that were at least 12 characters long, even if only lowercase letters, would take upwards of a year to crack, with passwords at least 15 characters long taking upwards of 1,000 years. Comparing their research with the Safety.com survey data, the average U.S. resident’s password could be hacked in under an hour, with many more potentially being hacked instantly.
 
Last edited by a moderator:

AG3S

Level 2
Oct 14, 2020
62
I believe the problem is not only the passwords. When Quantom computers come, even the most difficult passwords will be hackable. To avoid such situations the sevice providers should harden their services.

For example they should push for 2FA and more complex security measures in identifying the user. A good challange would be when the IP address of the user is changes completelly to a new IP range no matter the country. Then the user should be asked for the code which is sent to the email or his/her mobile phone.

I know it seems to be a little extreme but this is the future that we have to leave in!
 
F

ForgottenSeer 85179

It doesn't matter. No hacker is going to spend an hour on cracking your password, when he can buy a million passwords for a few dollars.
Right. Longest password doesn't help if database gets hacked and is insecure which is mostly the case.

I believe the problem is not only the passwords. When Quantom computers come, even the most difficult passwords will be hackable. To avoid such situations the sevice providers should harden their services.

For example they should push for 2FA and more complex security measures in identifying the user. A good challange would be when the IP address of the user is changes completelly to a new IP range no matter the country. Then the user should be asked for the code which is sent to the email or his/her mobile phone.

I know it seems to be a little extreme but this is the future that we have to leave in!
All these problems can be fixed with FIDO 2 hardware keys which exists for some time already.
But only very few services (like Microsoft) support that password-less authentication. That can also be combined with any 2FA
 

Cortex

Level 26
Verified
Top Poster
Well-known
Aug 4, 2016
1,465
My passwords are one hundred billion characters long ! :p:p
 

Attachments

  • Password.jpg
    Password.jpg
    299.3 KB · Views: 118

AG3S

Level 2
Oct 14, 2020
62
Server-side solutions aside, I believe the best thing would be to kind of force the users to use password managers. I know this also needs so much effort but when they get used to it, it will be easier to ask them to use stronger passwords.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top