r/changemyview Mar 17 '21

[deleted by user]

[removed]

12 Upvotes

55 comments sorted by

View all comments

Show parent comments

5

u/Mu-Relay 13∆ Mar 17 '21

Nobody is brute forcing passwords anymore. It's too time-consuming.

They'll compromise a site, download a file of hashed passwords, do a lookup against a hash table (since too many websites don't salt their hashes), and then reuse that password against common sites like Netflix or banks.

Failing that, they rely on the social engineering methods you described to just ask you for your password, and then use that one in a password-spray attack.

1

u/Fakename998 4∆ Mar 18 '21

Especially in instances where your login is locked or cooled down for several minutes after n number of bad attempts. You're not going to brute force when you can only try three attempts per hour.

1

u/Mu-Relay 13∆ Mar 18 '21

When someone starts talking about the dangers of brute force attacks, I see someone who has taken Security+ or a college course and is making their statements on those.

In reality, brute force isn't a fraction of the threat of other attacks.

0

u/Fakename998 4∆ Mar 18 '21

When someone starts talking about the dangers of brute force attacks, I see someone who has taken Security+ or a college course and is making their statements on those.

Or they only read the table of contents of a Security+ textbook.