ARL Logo
Risky Thinking
Tools and Ideas for Risk Assessment and Business Continuity
24 April, 2014
Easy Risk Register creation and maintenance.

How long is your password?

How much would it cost to crack your password using cloud computing?
Blue Gene / P

We’re constantly reminded that our passwords need to be long enough and complex enough to prevent brute force attacks

I came across an interesting reminder today that longer passwords need to be longer. This article by Thomas Roth notes that the cost of cracking all passwords of length 1 to 6 (assuming the use of an SHA-1 level algorithm for encrypting the password) is about $2 and takes about 49 minutes – comparable with the price and length of a trip to Starbucks. Thomas used rented capacity from Amazon’s cloud computing services to perform the attack.

What this demonstrates is that if an attacker has a means of testing passwords for correctness (either an intercepted message or a copy of an encrypted password), short passwords are exceedingly vulnerable – even to an individual hacker with a very modest computing budget.

The cost of a brute-force attack like this increases exponentially with password length. If we assume that most real world passwords are composed of lower case letters and numbers , the cost increases by a factor of about 36 for each additional character in the password. So a 7-character password would cost about $72, and an 8-character password $2592.

Choosing passwords which are composed of lower case, upper case, numbers, and punctuation symbols should improve this substantially. But passwords still have to be well chosen.

When you last thought up a password to meet these requirements did you:

If you did, I overestimated the cost of cracking your password. (Password cracking programs try more probable arrangements of characters first).

It’s difficult to choose random passwords by hand.

Unfortunately it’s also even more difficult to remember them.

Michael Z. Bell
November, 2010

Click here to let me know what you think of this article.

Want to know when the latest new article is available? Subscribe to the Risky Thinking Newsletter and keep up to date. It's free for people working in business continuity, disaster recovery, or risk management.

[ Back To Top ]


Note. Where trademarks are mentioned, they belong to their respective owners.

© Albion Research Ltd. 2014