Firewall Wizards mailing list archives
Re: "Proactive" Password Checking
From: Alec Muffett <alecm () coyote uk sun com>
Date: Wed, 10 Nov 1999 16:31:44 +0000
Now consider the password "maryhadalittlelamb"
let's see...
under Unix - 8 character truncation "maryhada"
also: implies password is definitely 8 chars long
password taken from the set of all lowercase letters
thus: set size of 26 symbols
there are 26^8 = 208827064576 passwords of length 8
which comprise only of lowercase letters
my dual-cpu 450MHz UltraSPARC-II can do 25000 crypts/sec/cpu
- certainly more if i could be bothered to optimise the code.
50000 crypts/second total, on my desktop.
208827064576 passwords at 50000 crypts/sec = 4176541 seconds
4176541 seconds = 48 days 8 hours 9 minutes 1 second
I can throw a rock from where I sit and hit about a dozen similar
machines; say I can get ahold of 10 for simplicity.
I can definitely crack your password in 4 days and 20 hours;
on average I will manage it in a little over two days.
...so...
I *do* hope you change your "secure" password on a weekly basis.
- alec
--
alec muffett, sun professional services, alec.muffett @ uk.sun.com
bananas are not the only fruit
Current thread:
- RE: "Proactive" Password Checking, (continued)
- RE: "Proactive" Password Checking Anton J Aylward (Nov 06)
- RE: "Proactive" Password Checking Kurt Buff (Nov 06)
- Re: "Proactive" Password Checking Frank O'Dwyer (Nov 18)
- RE: "Proactive" Password Checking Moore, James (Nov 06)
- RE: "Proactive" Password Checking Russ (Nov 06)
- Re: "Proactive" Password Checking REID FOX (Nov 06)
- RE: "Proactive" Password Checking Moore, James (Nov 08)
- RE: "Proactive" Password Checking Russ (Nov 09)
- RE: "Proactive" Password Checking Eric Toll (Nov 10)
- Re: "Proactive" Password Checking Joseph S D Yao (Nov 10)
- Re: "Proactive" Password Checking Alec Muffett (Nov 10)
- RE: "Proactive" Password Checking daN. (Nov 15)
- Re: "Proactive" Password Checking Eric Toll (Nov 10)
- Re: "Proactive" Password Checking Rick Smith (Nov 11)
- Re: "Proactive" Password Checking Eric Budke (Nov 14)
- Message not available
- Re: "Proactive" Password Checking Eric Budke (Nov 17)
- Re: "Proactive" Password Checking Rick Smith (Nov 11)
- Re: "Proactive" Password Checking Rick Smith (Nov 14)
- RE: "Proactive" Password Checking Andreas Gunnarsson (Nov 14)
- Re: "Proactive" Password Checking Dorian Moore (Nov 14)
