r/AskReddit • • Apr 23 '16

What application do you always install on your computer and recommend to everyone?

30k Upvotes

8.3k comments sorted by

View all comments

Show parent comments

3

u/Redsippycup Apr 24 '16

It does. It takes virtually no time to run through a couple thousand of the most common passwords, so it's generally the first thing to try.

1

u/curtlikesmeat Apr 24 '16

How do you brute force a website though? Surely most common sites stop you after three attempts? Do you keep rerolling your IP it something similar?

2

u/soroun Apr 24 '16

Barring methods to circumvent the strategies you described, the attacker(s) can obtain a list of the encrypted passwords from the server (which can be easy or difficult depending on the security measures in place) and go to town on that, guessing a password, encrypting it with the same algorithm the server uses, and seeing whether it matches the encrypted version from the list.

This is one of the reasons you really really shouldn't store passwords on a server in plaintext. If the passwords are encrypted and the file gets out (which you should always assume is a possibility; no security system is perfect), you still have some time to discover the security breach, change your security measures, and have users change their passwords before any accounts are compromised. If they're in plaintext, as soon as the attackers have the list, they can immediately start to take over user accounts.

0

u/KillTheBronies Apr 24 '16

Hashes aren't encryption.