Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Tips for selecting password length, Taken from 7-Zip help file

views
     
TSMussel
post Sep 15 2019, 09:46 PM, updated 7y ago

Casual
***
Junior Member
433 posts

Joined: Jun 2016


QUOTE
Here is an estimate of the time required for an exhaustive password search attack, when the password is a random sequence of lowercase Latin letters.

The most complex task for password search attack is SHA-256 calculation. Special SHA-256 hardware or GPU can be used to accelerate password search attack. Now modern GPU can provide about 10 times more performance for SHA-256 calculation than modern CPU. And special SHA-256 hardware can provide about 20 times more performance than GPU.

We suppose that one user with a budget of about $2000 (for GPUs) can check 10000 passwords per second and an organization with a budget of about 10^9 USD (one thousand million US dollars) can check 3 * 10^12 passwords per second. We also suppose that the processor in use doubles its performance every two years; so, each additional Latin letter of a long password adds about 9 years to an exhaustive key search attack.

The result is this estimate of the time to succeed in an attack:
Attached Image

I don't know if a password full of numerical digit is easy to hack?

This post has been edited by Mussel: Sep 15 2019, 09:49 PM
pakmulau
post Sep 15 2019, 10:00 PM

On my way
****
Junior Member
589 posts

Joined: Mar 2016
yeah may banking password and password manager all long one

need 15 seconds to type
hustlerism
post Sep 15 2019, 10:00 PM

Devil In Disguise
******
Senior Member
1,641 posts

Joined: Jun 2011
From: Sin City


No more passwords.

Start using passphrases
TSMussel
post Sep 15 2019, 10:13 PM

Casual
***
Junior Member
433 posts

Joined: Jun 2016


QUOTE(pakmulau @ Sep 15 2019, 10:00 PM)
yeah may banking password and password manager all long one

need 15 seconds to type
*
Given the below, a person can type about 3 characters per second...

QUOTE
The average person types between 38 and 40 words per minute (WPM), what translates into between 190 and 200 characters per minute (CPM). However, professional typists type a lot faster — on average between 65 and 75 WPM.


So a password which needs 15 seconds to type possibly is (15x3) 45 characters long.... Wow.



QUOTE(hustlerism @ Sep 15 2019, 10:00 PM)
No more passwords.

Start using passphrases
*
Good going. Looks like a more safer approach.
nodeffect
post Sep 25 2019, 12:44 AM

Your past does not equal your future.
******
Senior Member
1,281 posts

Joined: Jan 2003
From: Private


use a password generator ? https://my.norton.com/extspa/passwordmanager?path=pwd-gen

 

Change to:
| Lo-Fi Version
0.0134sec    1.31    6 queries    GZIP Disabled
Time is now: 16th December 2025 - 09:33 AM