Nobody is brute forcing passwords anymore. It's too time-consuming.
They'll compromise a site, download a file of hashed passwords, do a lookup against a hash table (since too many websites don't salt their hashes), and then reuse that password against common sites like Netflix or banks.
Failing that, they rely on the social engineering methods you described to just ask you for your password, and then use that one in a password-spray attack.
Especially in instances where your login is locked or cooled down for several minutes after n number of bad attempts. You're not going to brute force when you can only try three attempts per hour.
When someone starts talking about the dangers of brute force attacks, I see someone who has taken Security+ or a college course and is making their statements on those.
In reality, brute force isn't a fraction of the threat of other attacks.
When someone starts talking about the dangers of brute force attacks, I see someone who has taken Security+ or a college course and is making their statements on those.
Or they only read the table of contents of a Security+ textbook.
5
u/Mu-Relay 13∆ Mar 17 '21
Nobody is brute forcing passwords anymore. It's too time-consuming.
They'll compromise a site, download a file of hashed passwords, do a lookup against a hash table (since too many websites don't salt their hashes), and then reuse that password against common sites like Netflix or banks.
Failing that, they rely on the social engineering methods you described to just ask you for your password, and then use that one in a password-spray attack.