4 ms·
> Pure brute force is a bad metric, every 12 character password is equally good or bad by that standard. This is not entirely correct. If you had 12 q's in a
by tnicola 15y ago
> Pure brute force is a bad metric, every 12 character password is equally good or bad by that standard.
This is not entirely correct. If you had 12 q's in a row (or any 12 lower case letters) there would be 12^26 permutations that computer would have to check in order to guess it. Adding a capital Q would increase the number of permutations to 12^52. For each additional character set you throw in the mix, you would add the total number of those characters to the exponent part. Adding numbers would make it 12^62 etc. Not all 12 character passwords are created equal and some (like 12 numbers in a row) can quite possibly be brut forced.
- Codhisattva 15y agoAre brute force attacks always sequential?
- tnicola 15y agoI am not entirely familiar with modern day algorithms behind brut force attacks, but the math I described above is the theory behind them. I would imagine that it would have to be in some kind of ordered sequence so that you didn't miss any possibility and that your brut force time would average out (assuming infinite number of tries over rendom selection of passwords). It is, however, reasonable to assume that once the attack got part way though a word, that it would then try most common words etc. But assuming a random compilation of characters, sequential would be the most efficient over many number of tries. Note: the above does not apply to brut force attacks that try most common passwords and other techniques that include human element. It's just math behind the algorithm.