Bitcoin Forum
April 16, 2024, 05:31:09 PM *
News: Latest Bitcoin Core release: 26.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 »  All
  Print  
Author Topic: How long would take to break a 13 character password  (Read 4828 times)
Fraxinus
Legendary
*
Offline Offline

Activity: 1274
Merit: 1000



View Profile
September 22, 2016, 04:52:10 PM
 #21

It will take so many time you really have to be lucky to do it,that's the only hope.Computers are really powerful,however a 13 character password provides many possible combinations

Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
sukamasoto
Legendary
*
Offline Offline

Activity: 1148
Merit: 1006

Black Panther


View Profile
September 22, 2016, 05:38:04 PM
 #22


As per this link, with speed of 1,000,000,000 Passwords/sec, cracking a 8 character password composed using 96 characters takes 83.5 days

1,000,000,000 Passwords/sec => Typical for medium to large scale distributed computing, Supercomputers.



* reference
http://security.stackexchange.com/questions/43683/is-it-possible-to-brute-force-all-8-character-passwords-in-an-offline-attack



Just make sure that you're using 96 charaters password with 13 char, I'm sure even with Super Computer , it still need many years to crack it up


                                      ▄._      
                                       ▀█████████▀ 
                                     ,▄▓████████   
                                ╓▄▓███████████▀   
                           ╓▄▓███████▀╙.  ▀█     
                      ▄▄▓███████▀╙▄▄▄▄███         
                 ▄▄▓███████▀╙▄,  ▓███████        
           .▄▄▓██████▀▀╙▄▄▓████▌ ████████         
      .▄▄███████▀▀╙▄▄  ▐███████▌ ████████         
 .▄▄███████▀▀ ▐▄▄▓████ ▐███████▌ ████████         
╙█████▀▀▐▄▄▓  ████████ ▐███████▌ ████████        
 ╙▀ ▄▄▓█████  ████████ ▐███████▌ ████████         
    ████████  ████████ ▐███████▌ ████████         
    ████████  ████████ ▐███████▌ ████████             
xht
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250

hey you, yeah you, fuck you!!!


View Profile
September 22, 2016, 07:28:42 PM
 #23

Length is really the one factor that matters regarding password strength so using more character would be take more time to crack it.

pooya87
Legendary
*
Offline Offline

Activity: 3416
Merit: 10487



View Profile
September 23, 2016, 04:05:46 AM
 #24


As per this link, with speed of 1,000,000,000 Passwords/sec, cracking a 8 character password composed using 96 characters takes 83.5 days

1,000,000,000 Passwords/sec => Typical for medium to large scale distributed computing, Supercomputers.



* reference
http://security.stackexchange.com/questions/43683/is-it-possible-to-brute-force-all-8-character-passwords-in-an-offline-attack



Just make sure that you're using 96 charaters password with 13 char, I'm sure even with Super Computer , it still need many years to crack it up

first of all that link you posted is from a question that was asked 3 years ago and although there is not much changed but still it is kind of old.

also as it is also said there it depends on the algorithm used to create the the password hashes (in case it is used) so it may take a lot longer than that.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
doomistake
Hero Member
*****
Offline Offline

Activity: 1400
Merit: 571


View Profile
September 23, 2016, 04:22:24 AM
 #25

13 characters password is not that easy to hack. It may take a day or more if the password have numbers on it. Using bruteforce on it will take some time to crack the words that you put in your password but it will take a longer time on the number since it is not that easy to crack the sequence of the number. Since bruteforce trying all the common passwords that is in it's program it will be hard to crack the two words that you've put in you passwords since the other one is not in english.
zend7 (OP)
Hero Member
*****
Offline Offline

Activity: 658
Merit: 501

Hackers please hack me .... if you can :)


View Profile
September 23, 2016, 06:18:43 AM
 #26

Length is really the one factor that matters regarding password strength so using more character would be take more time to crack it.

Ok thanks everone for your help. Based on what I have read here I think I have understood what I have to do now. These 2 words together makes sense only to me and no one else in the face of earth (101% sure about this). What if I repeat this password 5 times and make it a 65 character long password and I change these 2 words and number sequences 3 times in the password and 2 times I keep it like that ?

How much would take to crack a 65 character long password made with .RAR Linux Ubuntu algorithm ?
leakingnoseee
Full Member
***
Offline Offline

Activity: 202
Merit: 100


View Profile
September 23, 2016, 06:36:01 AM
 #27

It is hard to say as it depends on how many numbers and signs it have
zend7 (OP)
Hero Member
*****
Offline Offline

Activity: 658
Merit: 501

Hackers please hack me .... if you can :)


View Profile
September 23, 2016, 07:31:56 PM
 #28

It is hard to say as it depends on how many numbers and signs it have

10 numbers and 5 signs and 50 letters, total of 65 characters. Algorithm used is of 7zip or Rar from the Ubuntu Linux which is one of the hardest to crack if you start from zero, especially if they don't know nothing about your password.

Now I have created a password with 2 sentences that makes sense only to me and have put numbers and signs that makes sense only to me. I guess this is the safest as it can be.
Indijanos
Full Member
***
Offline Offline

Activity: 148
Merit: 100



View Profile
September 24, 2016, 05:07:02 PM
 #29

I want to ask the tech guys here a few questions

I use for my all desktop wallets a password which is 13 character long and it consists of 2 words which only make senses to me and 2 number plus one special character, letters are small and capital ones.

How long would take from state sponsorship attack to bruteforce it ?

What about if I put this password to a RAR file which I keep all my documents and seeds encrypted , how much time if state sponsored attack have my file ?

Thanks in advance for your replies.

it would depend on the way of cracking the password. my friend and I were interested how long it wouldtake for a programm to crack our wifi pass using brute force... It took it almost 5 days, password was 8 characters long.

zend7 (OP)
Hero Member
*****
Offline Offline

Activity: 658
Merit: 501

Hackers please hack me .... if you can :)


View Profile
September 24, 2016, 05:41:38 PM
 #30

I want to ask the tech guys here a few questions

I use for my all desktop wallets a password which is 13 character long and it consists of 2 words which only make senses to me and 2 number plus one special character, letters are small and capital ones.

How long would take from state sponsorship attack to bruteforce it ?

What about if I put this password to a RAR file which I keep all my documents and seeds encrypted , how much time if state sponsored attack have my file ?

Thanks in advance for your replies.

it would depend on the way of cracking the password. my friend and I were interested how long it wouldtake for a programm to crack our wifi pass using brute force... It took it almost 5 days, password was 8 characters long.

Wifi has the weakest protocol to brute force it. If a single person with a Kali Linux installed within your reach it would take this program included there called aircrack ng about 24 hours for 2 characters to brute force so 4 days to a 8 character password.

However I am talking about one of the most secure encryption methods today which is .RAR or .7zip.

How come not a single cracker on this forum yet ?
Kprawn
Legendary
*
Offline Offline

Activity: 1904
Merit: 1073


View Profile
September 24, 2016, 05:58:50 PM
 #31

Just remember these passwords do not need to be brute forced with a massive database, if the hacker can manage to successfully apply

a Keylogger or even a "Man-in-the-middle" attack.  Wink  .... The effort in doing that, is a lot less than having to brute force a massive

password. In any way, no password being used on several different sites are bullet proof against attacks... It just makes it easier for a

hacker to find exploits on ANY of those sites, to get to your password. Use different passwords for different sites, and you will be a bit

more secure.  Wink

THE FIRST DECENTRALIZED & PLAYER-OWNED CASINO
.EARNBET..EARN BITCOIN: DIVIDENDS
FOR-LIFETIME & MUCH MORE.
. BET WITH: BTCETHEOSLTCBCHWAXXRPBNB
.JOIN US: GITLABTWITTERTELEGRAM
Fraxinus
Legendary
*
Offline Offline

Activity: 1274
Merit: 1000



View Profile
September 24, 2016, 07:53:45 PM
 #32

Just remember these passwords do not need to be brute forced with a massive database, if the hacker can manage to successfully apply

a Keylogger or even a "Man-in-the-middle" attack.  Wink  .... The effort in doing that, is a lot less than having to brute force a massive

password. In any way, no password being used on several different sites are bullet proof against attacks... It just makes it easier for a

hacker to find exploits on ANY of those sites, to get to your password. Use different passwords for different sites, and you will be a bit

more secure.  Wink

Hah yeaah Cheesy If they have a keylogger the whole thing happens to be a hella more easier

zend7 (OP)
Hero Member
*****
Offline Offline

Activity: 658
Merit: 501

Hackers please hack me .... if you can :)


View Profile
September 24, 2016, 08:58:01 PM
 #33

Just remember these passwords do not need to be brute forced with a massive database, if the hacker can manage to successfully apply

a Keylogger or even a "Man-in-the-middle" attack.  Wink  .... The effort in doing that, is a lot less than having to brute force a massive

password. In any way, no password being used on several different sites are bullet proof against attacks... It just makes it easier for a

hacker to find exploits on ANY of those sites, to get to your password. Use different passwords for different sites, and you will be a bit

more secure.  Wink


Latest news on TOR browser security advise websites says that MITM attacks were responsible for some hacking of some users but that flaw that permitted this attack was patched within 1 day (24 hour) from TOR browser developers.

I am sure I have not any keylogger on my machine yet. That is because no one gives a damn who am I but my question is just in case I need to be safe a 65 characters password which no one has a clue , how safe it is.

How safe it is if someone starts from 0 point trying to hack it, let's suppose he only have the RAR file and nothing else, doesn't know the source nor he does know what this file contains ? I think I am far ahead of the game now but need a confirmation from someone who has dealt with security day to day, someone who has worked at this field.
ivanst776
Legendary
*
Offline Offline

Activity: 1540
Merit: 1003



View Profile
September 24, 2016, 11:30:50 PM
 #34

I'm not 100% sure that we can trust these websites, but you should check:

https://howsecureismypassword.net/

http://random-ize.com/how-long-to-hack-pass/

Nobody should trust these websites because if their database or something else gets hacked then your password can be leaked.

OP I think that you and everybody else should not worry about the length of the 13+ chars password because can't be bruteforced as it will take so much time.

But we should be worried about our security because for a keylogger the password length doesn't matter to log.
Za1n
Legendary
*
Offline Offline

Activity: 1078
Merit: 1011



View Profile
September 25, 2016, 04:58:37 AM
Last edit: September 25, 2016, 05:12:07 AM by Za1n
 #35

Why even screw around? If you can come up with a 13 character password, add another few characters and some more randomness to it.

I wouldn't go for anything less than 16 characters for anything online, and if it is for something of significance you should be looking closer at 24 character + lengths, with lots of randomness, mixed case, numbers, and special symbols.

Here is another good site to glean some information on passwords. https://www.grc.com/haystack.htm

However, as others have already pointed out, do not use any passwords you actually intend to use at this or any of these sites, instead simply create similar test passwords to what you are thinking of using.
zend7 (OP)
Hero Member
*****
Offline Offline

Activity: 658
Merit: 501

Hackers please hack me .... if you can :)


View Profile
September 25, 2016, 12:24:59 PM
 #36

Why even screw around? If you can come up with a 13 character password, add another few characters and some more randomness to it.

I wouldn't go for anything less than 16 characters for anything online, and if it is for something of significance you should be looking closer at 24 character + lengths, with lots of randomness, mixed case, numbers, and special symbols.

Here is another good site to glean some information on passwords. https://www.grc.com/haystack.htm

However, as others have already pointed out, do not use any passwords you actually intend to use at this or any of these sites, instead simply create similar test passwords to what you are thinking of using.

I tried this website with a similar password as I don't to risk it. No one knows my real password to my files in my PC and to my electrum wallet. I tried a 40 character password which I can easily remember and it consisted of 32 lowercase letters 2 Uppercase letters 4 numbers and 2 symbols.

The website says to thoroughly trying to hack the password it needs a good 43 billion years Smiley . I hope they are right.
veleten
Legendary
*
Offline Offline

Activity: 2016
Merit: 1106



View Profile
September 27, 2016, 08:35:56 PM
 #37

I want to ask the tech guys here a few questions

I use for my all desktop wallets a password which is 13 character long and it consists of 2 words which only make senses to me and 2 number plus one special character, letters are small and capital ones.

How long would take from state sponsorship attack to bruteforce it ?

What about if I put this password to a RAR file which I keep all my documents and seeds encrypted , how much time if state sponsored attack have my file ?

Thanks in advance for your replies.

your password is

wX9uCPkTmFkHp

          ▄▄████▄▄
      ▄▄███▀    ▀███▄▄
   ▄████████▄▄▄▄████████▄
  ▀██████████████████████▀
▐█▄▄ ▀▀████▀    ▀████▀▀ ▄▄██
▐█████▄▄ ▀██▄▄▄▄██▀ ▄▄██▀  █
▐██ ▀████▄▄ ▀██▀ ▄▄████  ▄██
▐██  ███████▄  ▄████████████
▐██  █▌▐█ ▀██  ██████▀  ████
▐██  █▌▐█  ██  █████  ▄█████
 ███▄ ▌▐█  ██  ████████████▀
  ▀▀████▄ ▄██  ██▀  ████▀▀
      ▀▀█████  █  ▄██▀▀
         ▀▀██  ██▀▀
.WINDICE.████
██
██
██
██
██
██
██
██
██
██
██
██
████
      ▄████████▀
     ▄████████
    ▄███████▀
   ▄███████▀
  ▄█████████████
 ▄████████████▀
▄███████████▀
     █████▀
    ████▀
   ████
  ███▀
 ██▀
█▀

██
██
██
██
██
██
██
██
██
██
██
██
     ▄▄█████▄   ▄▄▄▄
    ██████████▄███████▄
  ▄████████████████████▌
 ████████████████████████
▐████████████████████████▌
 ▀██████████████████████▀
     ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
     ▄█     ▄█     ▄█
   ▄██▌   ▄██▌   ▄██▌
   ▀▀▀    ▀▀▀    ▀▀▀
       ▄█     ▄█
     ▄██▌   ▄██▌
     ▀▀▀    ▀▀▀

██
██
██
██
██
██
██
██
██
██
██
██
                   ▄█▄
                 ▄█████▄
                █████████▄
       ▄       ██ ████████▌
     ▄███▄    ▐█▌▐█████████
   ▄███████▄   ██ ▀███████▀
 ▄███████████▄  ▀██▄▄████▀
▐█ ▄███████████    ▀▀▀▀
█ █████████████▌      ▄
█▄▀████████████▌    ▄███▄
▐█▄▀███████████    ▐█▐███▌
 ▀██▄▄▀▀█████▀      ▀█▄█▀
   ▀▀▀███▀▀▀
████
  ██
  ██
  ██
  ██
  ██
  ██
  ██
  ██
  ██
  ██
  ██
  ██
████


▄▄████████▄▄
▄████████████████▄
▄████████████████████▄
███████████████▀▀  █████
████████████▀▀      ██████
▐████████▀▀   ▄▄     ██████▌
▐████▀▀    ▄█▀▀     ███████▌
▐████████ █▀        ███████▌
████████ █ ▄███▄   ███████
████████████████▄▄██████
▀████████████████████▀
▀████████████████▀
▀▀████████▀▀
iePlay NoweiI
I
I
I
[/t
startselect
Sr. Member
****
Offline Offline

Activity: 313
Merit: 250


View Profile
September 27, 2016, 09:36:45 PM
 #38

Do you more or less know what letter the password started with. You could cut down the time by a few years if you start on that letter. And perhaps if you eliminate letters that you know if definitely doesn't start with.
Gleb Gamow
In memoriam
VIP
Legendary
*
Offline Offline

Activity: 1428
Merit: 1145



View Profile
September 27, 2016, 11:01:22 PM
Last edit: September 28, 2016, 04:44:51 AM by Gleb Gamow
 #39

Thank you but let me tell you a bit more about it so you can give me a more accurate explanation (this one is accurate enough but I want to add a little info here)

My password consists of 2 words 1 is in English 1 is in another language there are 2 numbers and 1 special character in the end.

I have tried in a website which calculates how much is needed to crack it (the RAR) in that website. It says to me that even with 100.000 PC with 500.000 passwords per seconds it needs about 12.000 years and a bit more to crack. I think this is safe, as the computers there are cluster computers and not just 100.000 pc connected to each others.

A cluster computer have a tons of GPU to try to crack your passwords.

I know hackers cannot break it as the maximum they may have is 1,2 or about 20 clusters maximum but state has as many cluster as they want so regarding this is my question.

If this file goes in the hand of a national security agency how long it will take approximately to crack it ? If it is more than 1 month for me is OK, I will transfer my bitcoins to another wallet during this time without problems.

Edit: The English word cannot be found in any dictionary, it's a special word , people use it rarely and I checked a few dictionaries and couldn't find this word there.

Keep talkin' and Kramer Krackers will have it by the next commercial break: https://www.youtube.com/watch?v=HYvwYjPVra0
botija
Sr. Member
****
Offline Offline

Activity: 374
Merit: 250


View Profile
September 28, 2016, 03:12:02 AM
 #40

Qantum computer will do it instantly.
Pages: « 1 [2] 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!