Archive for August 16th, 2017

NIST’s new password security rules beg a question …..

August 16, 2017

How long does it take to hack a 16-character password?

=======

Last week, NIST ((the National Institute of Standards and Technology) issued new guidelines for password security.

After a review, NIST concluded that its former rules — passwords to include upper and lower case letters, numbers, special characters — made logins more complicated but didn’t materially improve online security.

Now, NIST is recommending using long, easy-to-remember phrases instead of relatively short strings of mixed letters, numbers and characters.

The rationale: the longer the string, the harder it is to crack.

For example some researchers concluded that it would only take 3 days to crack a password like “Tr0ub4dor&3” —  but over  550 years to crack the password “CorrectHorseBatteryStaple”

computer hacker

Oh really?

The story reminded me of a prior HomaFiles post that reported on a hacking test.

Hackers were given 1 hour to crack more than 16,000 cryptographically hashed passwords.

Her are the (frightening) results …

 

(more…)