4 ms·
And combine that with rainbow tables where appropriate :)
by uniqueuid 4y ago
And combine that with rainbow tables where appropriate :)
- Cupprum 4y agoRainbow tables are still being used?
- dementis 4y agoYes, because rainbow table attacks are still surprisingly effective. Although what is even more surprising is finding password still stored in plain text somewhere.
- Cupprum 4y agoIf the password complexity is small, than sure, you can use rainbow tables. But if the password get longer and longer, than have do you want to store the rainbow tables? Also if you have salted passwords, how are the rainbow tables going to help?
- dementis 4y agoNumber one password still in use with a total count of 4,929,113 is simply "password". https://nordpass.com/most-common-passwords-list/ https://nordpass.com/most-common-passwords-list/ Which is why there are Identity and Access Management (IAM) and Privileged Account Management (PAM) solutions that help protect against a users own laziness.
- avidiax 4y agoYes. As an example, your SSID name is used as a salt alongside your WPA2 passphrase to generate the final keys. That means that a rainbow table that covers the most common WPA2 SSID names could offer an instant solution, and narrow the search space if no solution is found.
- pseudo0 4y agoNot really. Rainbow tables are inflexible TMTOs that are slow to construct and have been made largely obsolete by advances in GPU cracking and more widespread use of good salts. Your WPA2 example doesn't hold up in the real world, where even default manufacturer SSIDs typically append a random number to avoid collisions with neighbors. One common pattern is manufacturer_####, that would be 10k rainbow tables per manufacturer and would only cover the defaults! Honestly if I hear someone in infosec start talking about rainbow tables in 2022, that's a good indicator that they have not cracked passwords in a long time, or they are just regurgitating what they learned to pass some basic security cert. Hashcat on a modern GPU is blazingly fast, and barring some really niche edge case, your best bet is just going to involve throwing more GPUs at the problem.