{"id":338,"date":"2025-03-11T20:26:18","date_gmt":"2025-03-11T20:26:18","guid":{"rendered":"https:\/\/securepathways.ca\/?p=338"},"modified":"2026-05-11T12:55:24","modified_gmt":"2026-05-11T19:55:24","slug":"some-passwords-can-be-cracked-in-an-instant-but-who-is-actually-to-blame","status":"publish","type":"post","link":"http:\/\/securepathways.ca\/index.php\/2025\/03\/11\/some-passwords-can-be-cracked-in-an-instant-but-who-is-actually-to-blame\/","title":{"rendered":"Some passwords can be cracked in an instant \u2013 but who is actually to blame?"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"338\" class=\"elementor elementor-338\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-51452b0e e-flex e-con-boxed e-con e-parent\" data-id=\"51452b0e\" data-element_type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f80dbe elementor-widget elementor-widget-text-editor\" data-id=\"f80dbe\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"article-layout__header-container\"><header class=\" a-article-header \">\n<h1 class=\" a-article-header__title \" dir=\"ltr\">Some passwords can be cracked in an instant \u2013 but who is actually to blame?<\/h1>\n<p class=\"a-article-header__lead\" dir=\"ltr\">Out of 193 million leaked passwords, researchers cracked around half of them within an hour. But the blame must In a recent report, security researchers from Kaspersky show how they have cracked passwords in seconds using modern graphics cards. For this to work, however, a number of conditions must be met. The blame for this does not lie solely with owners of online accounts and their &#8220;weak&#8221; passwords.<\/p>\n\n<\/header><\/div>\n<div class=\"article-layout__content-container\">\n<div class=\"article-layout__content\" dir=\"ltr\">\n<div class=\"article-content js-upscore-article-content-for-paywall\">\n<h3 id=\"nav_methodology_0\" class=\"subheading\">Methodology<\/h3>\n<a href=\"https:\/\/securelist.com\/passworde-brute-force-time\/112984\/\" target=\"_blank\" rel=\"external noopener\">In their experiments, the researchers reportedly<\/a>\u00a0used the computing power of Nvidia&#8217;s current high-end GPU GeForce RTX 4090 to crack passwords offline using a brute force or dictionary attack.\n\nThe brute force approach involves bluntly trying all conceivable combinations of characters until a password is guessed. The more computing power available, the faster the query. In dictionary attacks, cyber criminals draw on large lists of leaked log-in data and try them out.\n<div class=\"a-u-inline\">\n<div class=\"ho-text\" data-component=\"RecommendationBox\"><header class=\"mb-4\">\n<h3 class=\"inline-flex pb-2 pr-8 text-xl font-bold leading-none border-b-4 border-gray-800 dark:border-white\">Read also<\/h3>\n<\/header><section class=\"grid gap-6 md:gap-y-4\" data-component=\"TeaserList\" data-sneak-peek-elements-container=\"true\"><article class=\"ho-text flex\" data-component=\"TeaserContainer\" data-cid=\"\" data-content-id=\"3533748\" data-teaser-name=\"MinimalHorizontalTeaser\" data-upscore-object-id=\"7074549\">\n<figure class=\"w-24 mr-2 shrink-0 md:mr-4 md:w-40\" data-component=\"Image\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/heise.cloudimg.io\/v7\/_www-heise-de_\/imgs\/18\/3\/5\/3\/3\/7\/4\/8\/shutterstock_1866368917-d6dda7e0948d10a3.jpeg?force_format=avif%2Cwebp%2Cjpeg&amp;org_if_sml=1&amp;q=50&amp;width=160\" width=\"5000\" height=\"2809\" \/><\/figure>\n<div class=\"-translate-y-1\"><header data-component=\"TeaserHeader\">\n<h3 class=\"flex flex-col\"><span class=\"text-base leading-snug md:text-lg md:leading-snug max-w-prose font-bold group-hover:text-brand-branding dark:group-hover:text-white\" data-component=\"TeaserHeadline\"><span data-upscore-title=\"true\">Passwortsicherheit \u2013 Alles, was Sie wissen m\u00fcssen<\/span><\/span><\/h3>\n<\/header><\/div>\n<div><\/div>\n<\/article><\/section><\/div>\n<\/div>\nThe researchers used 192 million leaked passwords circulating on the darknet as a basis. In their experiments, they treated the passwords with the hash algorithm MD5, including the salt value, before cracking them. MD5 has long been considered insecure, but this is a theoretical attempt. They state that the computing power available to them can try 164 billion hashes per second.\n\nIn this scenario, they say they were able to crack 28% of passwords with upper and lower case letters in less than a minute. If numbers are added, the figure shrinks to three percent. And for 55 percent, the process would take longer than a year due to the complexity of the password. With optimized algorithms such as negram_seq, which calculate the probability of the next character, they were able to further increase the success rate.\n<div class=\"inread-cls-reduc\">\n<div>\n<div id=\"HEI_M_Incontent-2\" class=\"ad ad--inread\"><\/div>\n<\/div>\n<div>\n<div id=\"HEI_D_Incontent-2\" class=\"ad ad--inread\" data-google-query-id=\"CLmmsaHugowDFZwrBgAd3YAaKQ\" data-is-active=\"\"><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-82643ea e-flex e-con-boxed e-con e-parent\" data-id=\"82643ea\" data-element_type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-895d74f elementor-widget elementor-widget-html\" data-id=\"895d74f\" data-element_type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<style>\r\n\/* \u0641\u0642\u0637 \u0635\u0641\u062d\u0647 \u0645\u0642\u0627\u0644\u0647 *\/\r\n.article-layout__header-container,\r\n.article-layout__content-container{\r\n    max-width: 980px;\r\n    margin: 0 auto;\r\n    padding: 0 22px;\r\n}\r\n\r\n\/* \u0639\u0646\u0648\u0627\u0646 \u0648 \u0644\u06cc\u062f *\/\r\n.a-article-header__title{\r\n    font-size: clamp(34px, 4vw, 58px);\r\n    line-height: 1.2;\r\n    font-weight: 800;\r\n    letter-spacing: -1.5px;\r\n    color: #111827;\r\n    margin: 45px 0 22px;\r\n    text-align: left;\r\n}\r\n\r\n.a-article-header__lead{\r\n    font-size: 16px;\r\n    line-height: 2;\r\n    color: #4b5563;\r\n    max-width: 820px;\r\n    margin-bottom: 55px;\r\n}\r\n\r\n\/* \u0645\u062a\u0646 \u0645\u0642\u0627\u0644\u0647 *\/\r\n.article-layout__content,\r\n.article-content{\r\n    max-width: 760px;\r\n    margin: 0 auto;\r\n    font-size: 15.5px;\r\n    line-height: 2.15;\r\n    color: #1f2937;\r\n}\r\n\r\n\/* \u062a\u06cc\u062a\u0631\u0647\u0627\u06cc \u062f\u0627\u062e\u0644 \u0645\u0642\u0627\u0644\u0647 *\/\r\n.article-content h3.subheading{\r\n    font-size: 24px;\r\n    font-weight: 800;\r\n    color: #111827;\r\n    margin: 60px 0 22px;\r\n    padding-left: 16px;\r\n    border-left: 5px solid #1c64f2;\r\n}\r\n\r\n\/* \u0644\u06cc\u0646\u06a9\u200c\u0647\u0627 *\/\r\n.article-content a{\r\n    color: #1c64f2;\r\n    font-weight: 700;\r\n    text-decoration: none;\r\n}\r\n\r\n.article-content a:hover{\r\n    text-decoration: underline;\r\n}\r\n\r\n\/* \u0641\u0642\u0637 \u0628\u0627\u06a9\u0633 Read also *\/\r\n.article-content .a-u-inline{\r\n    margin: 55px 0;\r\n}\r\n\r\n.article-content .ho-text[data-component=\"RecommendationBox\"]{\r\n    background: #fff;\r\n    border: 1px solid rgba(15,23,42,.08);\r\n    border-radius: 28px;\r\n    padding: 34px;\r\n    box-shadow: 0 25px 70px rgba(15,23,42,.08);\r\n}\r\n\r\n\/* \u0639\u0646\u0648\u0627\u0646 Read also *\/\r\n.article-content .ho-text[data-component=\"RecommendationBox\"] > header h3{\r\n    font-size: 22px;\r\n    margin: 0 0 24px;\r\n    padding-left: 14px;\r\n    border-left: 5px solid #0ea5e9;\r\n    border-bottom: none !important;\r\n}\r\n\r\n\/* \u0622\u06cc\u062a\u0645 Read also *\/\r\n.article-content .ho-text article{\r\n    display: flex;\r\n    align-items: center;\r\n    gap: 22px;\r\n}\r\n\r\n\/* \u0641\u0642\u0637 \u0639\u06a9\u0633 \u062f\u0627\u062e\u0644 Read also *\/\r\n.article-content .ho-text figure{\r\n    width: 150px;\r\n    margin: 0 !important;\r\n    flex: 0 0 150px;\r\n}\r\n\r\n.article-content .ho-text figure img{\r\n    width: 150px !important;\r\n    height: 95px !important;\r\n    object-fit: cover;\r\n    border-radius: 16px;\r\n    margin: 0 !important;\r\n    box-shadow: 0 14px 30px rgba(0,0,0,.14);\r\n}\r\n\r\n\/* \u0645\u062a\u0646 Read also *\/\r\n.article-content .ho-text article h3,\r\n.article-content .ho-text article span{\r\n    font-size: 20px !important;\r\n    line-height: 1.5 !important;\r\n    font-weight: 800;\r\n    color: #111827;\r\n}\r\n\r\n\/* \u0639\u06a9\u0633\u200c\u0647\u0627\u06cc \u0645\u0633\u062a\u0642\u06cc\u0645 \u062f\u0627\u062e\u0644 \u0645\u062a\u0646\u060c \u0646\u0647 \u0639\u06a9\u0633\u200c\u0647\u0627\u06cc \u0647\u062f\u0631 \u0648 \u0646\u0647 \u0641\u0648\u062a\u0631 *\/\r\n.article-content > img,\r\n.article-content > p > img{\r\n    width: 100%;\r\n    max-width: 760px;\r\n    height: auto;\r\n    display: block;\r\n    margin: 50px auto;\r\n    border-radius: 26px;\r\n    object-fit: cover;\r\n    box-shadow: 0 25px 65px rgba(15,23,42,.16);\r\n}\r\n\r\n\/* \u062d\u0630\u0641 \u0628\u0647\u0645\u200c\u0631\u06cc\u062e\u062a\u06af\u06cc\u200c\u0647\u0627\u06cc \u0627\u0636\u0627\u0641\u0647 *\/\r\n.article-content .inread-cls-reduc,\r\n.article-content .ad{\r\n    display: none !important;\r\n}\r\n\r\n\/* \u0645\u0648\u0628\u0627\u06cc\u0644 *\/\r\n@media(max-width: 768px){\r\n    .article-layout__header-container,\r\n    .article-layout__content-container{\r\n        padding: 0 16px;\r\n    }\r\n\r\n    .a-article-header__title{\r\n        font-size: 30px;\r\n        letter-spacing: -1px;\r\n        margin-top: 35px;\r\n    }\r\n\r\n    .a-article-header__lead{\r\n        font-size: 15px;\r\n        line-height: 1.9;\r\n    }\r\n\r\n    .article-layout__content,\r\n    .article-content{\r\n        max-width: 100%;\r\n        font-size: 15px;\r\n    }\r\n\r\n    .article-content .ho-text[data-component=\"RecommendationBox\"]{\r\n        padding: 24px;\r\n        border-radius: 22px;\r\n    }\r\n\r\n    .article-content .ho-text article{\r\n        flex-direction: column;\r\n        align-items: flex-start;\r\n    }\r\n\r\n    .article-content .ho-text figure,\r\n    .article-content .ho-text figure img{\r\n        width: 100% !important;\r\n        height: auto !important;\r\n    }\r\n}\r\n<\/style>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Some passwords can be cracked in an instant \u2013 but who is actually to blame? Out of 193 million leaked passwords, researchers cracked around half of them within an hour. But the blame must In a recent report, security researchers from Kaspersky show how they have cracked passwords in seconds using modern graphics cards. For [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":341,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-338","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"http:\/\/securepathways.ca\/index.php\/wp-json\/wp\/v2\/posts\/338","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/securepathways.ca\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/securepathways.ca\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/securepathways.ca\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/securepathways.ca\/index.php\/wp-json\/wp\/v2\/comments?post=338"}],"version-history":[{"count":4,"href":"http:\/\/securepathways.ca\/index.php\/wp-json\/wp\/v2\/posts\/338\/revisions"}],"predecessor-version":[{"id":938,"href":"http:\/\/securepathways.ca\/index.php\/wp-json\/wp\/v2\/posts\/338\/revisions\/938"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/securepathways.ca\/index.php\/wp-json\/wp\/v2\/media\/341"}],"wp:attachment":[{"href":"http:\/\/securepathways.ca\/index.php\/wp-json\/wp\/v2\/media?parent=338"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/securepathways.ca\/index.php\/wp-json\/wp\/v2\/categories?post=338"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/securepathways.ca\/index.php\/wp-json\/wp\/v2\/tags?post=338"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}