Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

Your Password Can Probably be Cracked Faster Than You’d Think

Your Password Can Probably be Cracked Faster Than You’d Think

Whether you’re talking about identity theft, data breaches, or any other form of cybercrime, one of the leading causes of successful cyberattacks is the use of insufficiently secure passwords. Just how easy is it for someone to bypass such a password? Let’s consider the facts.

How to Crack a Password

Cybercriminals come correct, first of all. Not only do many of them have access to some pretty sophisticated tools and resources, they go about their selfish and deceitful activities with a strategy based on the average user’s online conduct.

For the cybercriminal, bypassing a password is really a numbers game. Chances are good that, if they try some commonly used passwords, a cybercriminal will eventually hit pay dirt. For instance, a cybercriminal’s first guesses could look like the following:

  • 123456789
  • guest
  • qwerty
  • password
  • a1b2c3

Since these are some of the world’s most common passwords—with an estimated 10 to 20% of accounts using a similar password—trying different variations of them or adding one or two symbols gives a cybercriminal a pretty good chance of getting in.

If we imagine ourselves to be cybercriminals, this knowledge helps to simplify our process immensely. If we invest in a password cracking tool, which effectively just tries every dictionary word and randomized combination of characters, increasing in length as it goes, chances are good that we will ultimately get in.

It’s just like trying to guess a combination lock number. While it’s going to take some time, you could try every possible combination—1-1-1, 1-1-2, 1-1-3—until you either get it, or the bike’s owner is back and not-so-politely asking you to step away from their property. 

The more variables there are to try, the more possible options there are—increasing at exponential rates, making it impossible to manually try every single combination. A computer, on the other hand, could try…and much, much faster. That’s how a password-cracking tool operates.

How Long Before a Password is Cracked?

It all depends on the password. Many of the tools that these cybercriminals will use will try the usual suspects first, and will therefore crack the password immediately. The shorter, weaker passwords can take fractions of a second, with these tools testing millions of potential credentials in that time.

It also depends on the hardware the cybercriminal is using, as a more powerful system will allow the attacker to test potential passwords that much faster. Let’s go over how speedily a reasonably powerful laptop could crack a password, based on how long the password is, and how complicated it is:

As pictured, weak—or short and simple passwords—would fold immediately, holding out for a few seconds or minutes at best. However, once a password is designed to be longer and more complex, the likelihood of a password being cracked within someone’s lifetime becomes far smaller…arguably impossible.

That is, however, assuming that your password’s length and complexity aren’t wholly reliant on a combination of otherwise common (and therefore, insecure) words or phrases. Sure, “!password12345” may seem to meet some of the basic requirements for a password—and based on the password chart above, should take a million years to figure out—the use of common password trends makes it far easier to figure out.

This is precisely why we always advocate for more stringent password practices to ensure each and every one is sufficiently secure. These practices include the aforementioned length and complexity requirements, and avoiding things that could be guessed somewhat easily, including pet names, birthdays, and other common factors. Of course, passwords should never be used more than once, as in, you need a separate password for each account you’re securing.

It is also important to keep in mind that the results generated above could be accomplished using resources that are out there and available, using a basic tool on a common laptop. An invested cybercriminal very well could have additional resources at their disposal, things like botnets and significant cloud resources, along with the hardware needed to power through a brute force attempt much faster than our hypothetical mid-range laptop could.

The big takeaway: ALWAYS use strong and secure passwords.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Friday, 25 April 2025

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud User Tips Network Security Hardware Internet Efficiency IT Support Malware Google Privacy Email Workplace Tips Phishing Computer IT Services Collaboration Hosted Solutions Users Mobile Device Ransomware Workplace Strategy Quick Tips Microsoft Cybersecurity Small Business Passwords Communication Data Backup Smartphone Backup Saving Money VoIP Business Management Android Smartphones Upgrade communications Managed Service Mobile Devices Disaster Recovery Data Recovery Browser Social Media Managed IT Services Microsoft Office Windows Tech Term Network Remote Internet of Things Current Events Facebook Automation Productivity Artificial Intelligence Covid-19 Cloud Computing Gadgets Server Managed Service Provider AI Remote Work Miscellaneous Outsourced IT Information Holiday Encryption Employee/Employer Relationship Spam Office Compliance Windows 10 Business Continuity Data Management Government Training Bandwidth Windows 10 Blockchain Wi-Fi Virtualization Business Technology Mobile Office Data Security Two-factor Authentication Apps Budget Apple Networking Mobile Device Management App Gmail Vendor BYOD Employer-Employee Relationship Chrome Managed Services Voice over Internet Protocol Avoiding Downtime Marketing How To BDR WiFi Applications Computing Information Technology Access Control Office 365 IT Support Tip of the week Conferencing Hacker Retail Healthcare Storage Password Website Bring Your Own Device Managed IT Services HIPAA Operating System Router Big Data Risk Management Virtual Private Network Help Desk Health Analytics Office Tips Computers Augmented Reality Telephone Scam Data loss Cooperation Free Resource Project Management Windows 7 Firewall Microsoft 365 Going Green Patch Management Save Money Remote Monitoring Solutions End of Support Vulnerability The Internet of Things Vendor Management Cybercrime Physical Security Social Display Printer Windows 11 Monitoring Paperless Office 2FA Infrastructure Excel Customer Service Document Management Remote Workers Downloads Wireless Technology Maintenance iPhone Licensing Antivirus Sports Mouse Entertainment Vulnerabilities Data Privacy Word Administration Images 101 Telephone System Multi-Factor Authentication Mobility Cost Management Robot Safety Settings Wireless Printing Employees Content Filtering Integration IT Management YouTube Meetings VPN User Tip Modem Mobile Security Processor Cryptocurrency Holidays Computer Repair Data Storage Virtual Desktop Customer Relationship Management Data storage LiFi Smart Technology Supply Chain Video Conferencing Managed Services Provider Outlook Saving Time Virtual Machines Professional Services Hacking Machine Learning Presentation Money Humor Managed IT Service Alerts SQL Server Technology Care Hacks Server Management Download Net Neutrality Scary Stories Private Cloud Financial Data Identity Theft History Fun Business Communications Superfish IP Address Browsers Smartwatch Deep Learning Connectivity IT Twitter Break Fix Scams Azure Hybrid Work Upload Procurement Error Social Network Telework Education Cyber security Social Engineering Multi-Factor Security Tech Human Resources Recovery CES IoT Communitications Remote Computing Dark Web Cables Hard Drives Mobile Computing Trends Supply Chain Management Customer Resource management FinTech Tablet Regulations Search Google Calendar Term Google Apps Domains Data Analysis Best Practice Star Wars IT Assessment Alert Microsoft Excel IT Maintenance Staff Value Business Intelligence Dark Data Refrigeration Managed IT Gamification Flexibility Buisness File Sharing Organization IT solutions Social Networking How To Legislation Shortcuts Public Speaking Legal Lithium-ion battery Fileless Malware Digital Security Cameras Business Growth Smart Devices Notifications Ransmoware Wearable Technology Memory Vendors Entrepreneur Content Remote Working Travel Techology Health IT Google Maps Motherboard Data Breach Cortana Comparison Google Play Be Proactive Directions Videos Alt Codes Assessment Electronic Health Records Permissions Workforce Downtime Unified Threat Management Wasting Time Threats Undo Unified Threat Management Hosted Solution Trend Micro Specifications Security Cameras Workplace Strategies Fraud Meta Microchip Typing Internet Exlporer Software as a Service Username Managing Costs Amazon Network Congestion Google Drive User Error eCommerce Knowledge Black Friday SSID Virtual Assistant Outsource IT Application Database Surveillance Point of Sale IT Technicians Virtual Machine Environment 5G Media IBM Google Docs Proxy Server Reviews Unified Communications Cookies Experience Cyber Monday Medical IT Hotspot Transportation Small Businesses Bitcoin Network Management Tactics Development Running Cable Tech Support Mirgation Hypervisor Displays Monitors Google Wallet Shopping Nanotechnology Optimization PowerPoint Language Employer/Employee Relationships Outsourcing Windows 8 Addiction Laptop Websites Management PCI DSS Chatbots Navigation Competition Drones SharePoint Gig Economy Screen Reader Electronic Medical Records Distributed Denial of Service Workplace Computing Infrastructure Teamwork Hiring/Firing Service Level Agreement Internet Service Provider Halloween Regulations Compliance Identity Writing Evernote Paperless Lenovo User Bookmark Smart Tech Memes Virtual Reality Co-managed IT

Blog Archive