Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

Your Password Can Probably be Cracked Faster Than You’d Think

Your Password Can Probably be Cracked Faster Than You’d Think

Whether you’re talking about identity theft, data breaches, or any other form of cybercrime, one of the leading causes of successful cyberattacks is the use of insufficiently secure passwords. Just how easy is it for someone to bypass such a password? Let’s consider the facts.

How to Crack a Password

Cybercriminals come correct, first of all. Not only do many of them have access to some pretty sophisticated tools and resources, they go about their selfish and deceitful activities with a strategy based on the average user’s online conduct.

For the cybercriminal, bypassing a password is really a numbers game. Chances are good that, if they try some commonly used passwords, a cybercriminal will eventually hit pay dirt. For instance, a cybercriminal’s first guesses could look like the following:

  • 123456789
  • guest
  • qwerty
  • password
  • a1b2c3

Since these are some of the world’s most common passwords—with an estimated 10 to 20% of accounts using a similar password—trying different variations of them or adding one or two symbols gives a cybercriminal a pretty good chance of getting in.

If we imagine ourselves to be cybercriminals, this knowledge helps to simplify our process immensely. If we invest in a password cracking tool, which effectively just tries every dictionary word and randomized combination of characters, increasing in length as it goes, chances are good that we will ultimately get in.

It’s just like trying to guess a combination lock number. While it’s going to take some time, you could try every possible combination—1-1-1, 1-1-2, 1-1-3—until you either get it, or the bike’s owner is back and not-so-politely asking you to step away from their property. 

The more variables there are to try, the more possible options there are—increasing at exponential rates, making it impossible to manually try every single combination. A computer, on the other hand, could try…and much, much faster. That’s how a password-cracking tool operates.

How Long Before a Password is Cracked?

It all depends on the password. Many of the tools that these cybercriminals will use will try the usual suspects first, and will therefore crack the password immediately. The shorter, weaker passwords can take fractions of a second, with these tools testing millions of potential credentials in that time.

It also depends on the hardware the cybercriminal is using, as a more powerful system will allow the attacker to test potential passwords that much faster. Let’s go over how speedily a reasonably powerful laptop could crack a password, based on how long the password is, and how complicated it is:

As pictured, weak—or short and simple passwords—would fold immediately, holding out for a few seconds or minutes at best. However, once a password is designed to be longer and more complex, the likelihood of a password being cracked within someone’s lifetime becomes far smaller…arguably impossible.

That is, however, assuming that your password’s length and complexity aren’t wholly reliant on a combination of otherwise common (and therefore, insecure) words or phrases. Sure, “!password12345” may seem to meet some of the basic requirements for a password—and based on the password chart above, should take a million years to figure out—the use of common password trends makes it far easier to figure out.

This is precisely why we always advocate for more stringent password practices to ensure each and every one is sufficiently secure. These practices include the aforementioned length and complexity requirements, and avoiding things that could be guessed somewhat easily, including pet names, birthdays, and other common factors. Of course, passwords should never be used more than once, as in, you need a separate password for each account you’re securing.

It is also important to keep in mind that the results generated above could be accomplished using resources that are out there and available, using a basic tool on a common laptop. An invested cybercriminal very well could have additional resources at their disposal, things like botnets and significant cloud resources, along with the hardware needed to power through a brute force attempt much faster than our hypothetical mid-range laptop could.

The big takeaway: ALWAYS use strong and secure passwords.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Wednesday, 11 June 2025

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud Network Security User Tips Hardware Internet Efficiency IT Support Privacy Malware Google Email Computer Phishing Workplace Tips IT Services Collaboration Users Hosted Solutions Mobile Device Workplace Strategy Ransomware Quick Tips Small Business Cybersecurity Microsoft Communication Passwords Data Backup Saving Money Smartphone Backup Managed Service Business Management VoIP Smartphones Android Upgrade Mobile Devices communications Disaster Recovery Browser Data Recovery Managed IT Services Social Media Windows Microsoft Office Remote Current Events Tech Term Network Internet of Things Productivity Artificial Intelligence Facebook Automation Gadgets Cloud Computing AI Covid-19 Remote Work Miscellaneous Server Managed Service Provider Outsourced IT Holiday Information Employee/Employer Relationship Encryption Spam Compliance Training Office Windows 10 Data Management Business Continuity Government Windows 10 Bandwidth Virtualization Wi-Fi Blockchain Business Technology IT Support Data Security Apps Two-factor Authentication Mobile Office Vendor Mobile Device Management Chrome Gmail Budget Apple Networking Managed Services Voice over Internet Protocol App Employer-Employee Relationship BYOD Applications Tip of the week WiFi Conferencing How To BDR Computing Hacker Information Technology Avoiding Downtime Access Control HIPAA Marketing Office 365 Analytics Office Tips Augmented Reality Retail Storage Help Desk Password Bring Your Own Device Big Data Managed IT Services Healthcare Operating System Computers Virtual Private Network Risk Management Website Health Router Firewall Document Management Windows 11 Monitoring 2FA The Internet of Things Scam Data loss Excel Social Remote Workers Telephone Going Green Patch Management Save Money Remote Monitoring End of Support Vulnerability Customer Service Cooperation Free Resource Vendor Management Project Management Cybercrime Windows 7 Physical Security Microsoft 365 Display Printer Paperless Office Solutions Infrastructure Outlook Machine Learning User Tip Modem Money Mobile Security Processor Humor Holidays Safety Data Storage Maintenance Sports Smart Technology Supply Chain Antivirus Mouse Video Conferencing Managed Services Provider Virtual Machines Professional Services Saving Time Administration Managed IT Service Downloads iPhone Robot Customer Relationship Management Licensing Settings Vulnerabilities Wireless Entertainment Printing Data Privacy Content Filtering Hacking IT Management YouTube Meetings Images 101 Presentation VPN Mobility Telephone System Cryptocurrency Multi-Factor Authentication Wireless Technology Cost Management Computer Repair Virtual Desktop Data storage LiFi Employees Word Integration SharePoint Username Managing Costs Amazon Electronic Medical Records Halloween Black Friday SSID Refrigeration eCommerce Public Speaking Lenovo Database Surveillance Virtual Assistant Outsource IT Writing Lithium-ion battery IT Technicians Virtual Machine Environment Virtual Reality Media Entrepreneur Scary Stories Private Cloud Cyber Monday Medical IT Proxy Server Reviews Hacks Server Management Cookies Superfish Tactics Development Identity Theft Hotspot Transportation Small Businesses Fun Deep Learning Mirgation Hypervisor Displays Twitter Error PowerPoint Shopping Undo Nanotechnology Optimization Addiction Education Language Employer/Employee Relationships Outsourcing Social Engineering Management PCI DSS Chatbots Remote Computing Navigation Screen Reader Distributed Denial of Service Workplace Gig Economy Mobile Computing Service Level Agreement Internet Service Provider Tablet Computing Infrastructure Teamwork Hiring/Firing Search Evernote Paperless Regulations Compliance Application Best Practice Identity Alert Smart Tech Memes Buisness File Sharing Co-managed IT Dark Data Bookmark Managed IT IBM Legal Download Net Neutrality IT solutions Alerts SQL Server Technology Care How To Business Communications Financial Data Business Growth History Notifications Connectivity IT Travel Break Fix Scams Browsers Smartwatch Techology Upload Procurement Google Maps Azure Hybrid Work Cortana Multi-Factor Security Tech Human Resources Social Network Telework Alt Codes Cyber security IoT Communitications Downtime Unified Threat Management Dark Web Cables CES Competition Unified Threat Management Trends Supply Chain Management Hosted Solution Google Calendar Term Google Apps Customer Resource management FinTech Typing Regulations Star Wars IT Assessment Microsoft Excel IT Maintenance Network Congestion Data Analysis Google Drive User Error Gamification Flexibility User Staff Value Business Intelligence Knowledge Legislation Shortcuts Organization Social Networking Smart Devices Point of Sale Ransmoware 5G Fileless Malware Digital Security Cameras IP Address Google Docs Content Remote Working Unified Communications Wearable Technology Memory Vendors Experience Running Cable Tech Support Comparison Google Play Be Proactive Health IT Bitcoin Network Management Motherboard Data Breach Google Wallet Assessment Electronic Health Records Permissions Workforce Monitors Directions Videos Recovery Wasting Time Threats Laptop Websites Specifications Security Cameras Workplace Strategies Hard Drives Windows 8 Trend Micro Domains Drones Internet Exlporer Software as a Service Fraud Meta Microchip

Blog Archive