What is the reliability of this password creation method?

  • Thread starter Thread starter Gomar
  • Start date Start date
Click For Summary

Discussion Overview

The discussion revolves around the reliability of a specific password creation method, particularly focusing on the estimated time it would take to crack a randomly generated 20-character password composed solely of lowercase letters. Participants explore the implications of password strength in relation to cracking speeds and algorithms.

Discussion Character

  • Technical explanation
  • Debate/contested

Main Points Raised

  • One participant calculates that a 20-character password made of lowercase letters would take approximately 659,000,000 years to crack at a speed of 1 trillion passwords per second.
  • Another participant agrees with the initial calculation but suggests a slightly different estimate of around 656,744,329.448937 years based on the same cracking speed.
  • Some participants note that even at high cracking speeds, they feel secure that their encrypted files would remain safe for at least 6 million years, assuming only lowercase letters are used.
  • There is a mention of cracking algorithms that may prioritize certain combinations based on human memorability, which could affect the actual security of passwords despite theoretical estimates.

Areas of Agreement / Disagreement

Participants generally agree on the vast time estimates for cracking the passwords but express differing views on the implications of password selection and the effectiveness of cracking algorithms. The discussion remains unresolved regarding the practical security of passwords against targeted cracking methods.

Contextual Notes

Participants acknowledge that the time estimates are based on theoretical calculations and do not account for specific strategies employed by cracking algorithms that may reduce the effective security of certain passwords.

Gomar
Messages
20
Reaction score
0
https://www.grc.com/haystack.htm

enter a random 20 character pw made of only lower case letters.
(However, x100 as I am using 1T not 100T pws/sec; thus:
65.90 thousand centuries x100 = 6590 thousand centuries)

answer: 659,000,000years.

is that correct?
 
Computer science news on Phys.org
Gomar said:
https://www.grc.com/haystack.htm

enter a random 20 character pw made of only lower case letters.
(However, x100 as I am using 1T not 100T pws/sec; thus:
65.90 thousand centuries x100 = 6590 thousand centuries)

answer: 659,000,000years.

is that correct?
I guess, if I understand what you're asking. 65,900 X 100 centuries = 6,590,000 centuries = 659,000,000 years

Note: I didn't visit the site you showed, so I don't know what your question has to do with anything.
 
20725274851017785518433805270 looks about right ...

at 1 Tpws/s ... maybe 656,744,329.448937 yrs is a slightly better rough guess?

20725274851017785518433805270 / 1 T / (60 * 60 * 24 * 365.25)
 
NemoReally said:
20725274851017785518433805270 looks about right ...

at 1 Tpws/s ... maybe 656,744,329.448937 yrs is a slightly better rough guess?

20725274851017785518433805270 / 1 T / (60 * 60 * 24 * 365.25)


Thanks for atleast visiting the site prior to posting an answer.
Yes, you are correct. Even using 100T pws/sec (their speed), I could rest assured spooks won't break my encrypted files in atleast 6m years even if using only lower case letters.
 
Gomar said:
Thanks for atleast visiting the site prior to posting an answer.
Yes, you are correct. Even using 100T pws/sec (their speed), I could rest assured spooks won't break my encrypted files in atleast 6m years even if using only lower case letters.

Ah, well, I think the site does mention (I only glanced at it) that a cracking algorithm would try certain combinations first as being more likely (people have to remember them and many password generating algorithms have a filter that restricts the passwords to "human memorable / speakable" passwords). The time given is that needed to test all the combinations. If the cracking algorithm just rolls its sleeves up, starts at "aaaaa..." and your password happens to be "aaaaa..." then your secret stash of pi porn will become viral in no time (well, at least in the maths community :cool:)
 

Similar threads

  • · Replies 3 ·
Replies
3
Views
3K
Replies
4
Views
4K
  • · Replies 3 ·
Replies
3
Views
767
  • · Replies 94 ·
4
Replies
94
Views
14K
  • · Replies 1 ·
Replies
1
Views
3K