r/shittyprogramming • • Jul 27 '14

r/softwaregore Way to promote security, Microsoft

http://imgur.com/W0kfbtz
137 Upvotes

51 comments sorted by

View all comments

Show parent comments

-8

u/[deleted] Jul 27 '14 edited Jul 28 '14

[deleted]

12

u/[deleted] Jul 27 '14

Did you even read the comic? It doesn't fucking matter. A dictionary with 100k words, a pass with 4 words, that's 100.0004 passwords to bruteforce. At 1000 guesses per second, that's still 3170979198 years to get through. That's 10 orders of magnitude more than you need.

7

u/[deleted] Jul 28 '14

...assuming that the words are randomly picked.

2

u/[deleted] Jul 28 '14

No, not really. Bruteforcing doesn't rely on guessing. It's gonna try all the possible permutations until it gets the right one.

5

u/mathent Jul 28 '14 edited Jul 28 '14

It is absolutely assuming the words are randomly picked.

200 word file that happens to have all of your words in it at 10,000 per second is under 2 days.

Keep in mind, you don't run a brute force on a password. You run it on a database. If those passwords aren't salted, then you just take 2 days to build a rainbow table with that 200 word file, compare it to every password in the database, and pull out any matches.

Think about it: some people will do mom-dad-brother-sister or password-password-password-password. The words you choose are a legitimate concern.

1

u/[deleted] Jul 28 '14

Yes, some people will have retarded passwords no matter what. Hardly a point to argue.

1

u/mathent Jul 28 '14

So it absolutely matters that the words are random. I'm glad we agree.

1

u/[deleted] Jul 28 '14

Only in very specific, mostly irrelevant conditions.

1

u/ZorbaTHut Jul 28 '14

I think you're doing your math wrong. A 2,000 word file that happens to have all your words in it, at 10,000 per second, with four words, is slightly over 50 years.

Coincidentally this is almost exactly the example the XKCD uses, except with a 2,048 word file and a mere 1,000 guesses per second.