
Hallo zusammen, ich bin wieder zurück mit dem 2026-Update unserer Passworttabelle! Computer und insbesondere GPUs werden nicht nur immer schneller, sondern KI kann uns auch dabei helfen, Setups auf neue und neuartige Weise zu erstellen, um schneller als je zuvor zu knacken. Diese Tabelle gibt einen Überblick über die Zeit, die ein Computer benötigt, um Ihr Passwort brutal zu erzwingen. Sie gibt keinen Aufschluss darüber, wie schnell ein Hacker Ihr Passwort knacken kann (insbesondere, wenn Sie Ihre Passwörter wiederverwenden – hören Sie bitte damit auf), sondern stellt das BEST-Case-Szenario für Sie dar. Es ist ein gutes Bild, um den Leuten zu zeigen, warum bessere Passwörter zu besserer Cybersicherheit führen können, aber letztendlich ist es nur eines von vielen Tools, mit denen wir über den Schutz im Internet sprechen können!
Datenquelle: Daten, die durch unabhängige Datenerfassung und Recherche aus mehreren Quellen zu Hashing-Funktionen, GPU-Leistung und zugehörigen Daten zusammengestellt wurden. Die Methodik, Annahmen und weitere Daten finden Sie unter www.hivesystems.com/password
Verwendete Tools: Illustrator und Google Sheets
Von hivesystems
29 Kommentare
I never understood these. Can’t you just put latency in the system that checks the entered password?
Maybe you should declare that it doesnt work that easy that someone can just repeadetly guess your lets say FB account password. This needs the hashed passwords to be leaked in the first place aka critical leakage has already happened.
It assumes they already have access to the hashes, which is wild.
For banks etc, they don’t. Rate-limiters will give them a few tries, not the billions they need.
It’s weird if someone spend 64 grand in order to get into my space account from 16 years ago…. I’m sorry bro you’re still not getting in my top 8.
I’m genuinely curious what the math looks like if it’s numbers and lowercase letters only, if math on that exists.. i feel like that would also be fairly common for people to use..
Reminder that the govt doesn’t need your password to just store your encrypted data and decrypt it later when computer is cheaper.
Also don’t click on shit or trust people. Because that’s how hacks actually mostly taken.
Interesting data. One question though – why isn’t everything above 50 years green? A password that takes 50 years to brute force will not be brute forced, right?
Also important to keep in mind this doesn’t include other methods of figuring out passwords like dictionary attacks or excluding unlikely password entries
For me it is still easier though to remember 20 digits than a mixture of 10 letters in upper and lowercase, digits and symbols. Each additional digit means a ten fold increase of the time to crack the password.
A better measurement that time is dollars though. A state actor who wants to crack your password by brute force, will use a lot lot more computer compute than those 16 consumer GPUs. If cracking your password costs $10,000, even a spy agency with deep pockets will only invest that money if you are a high profile target. If you add just two digits, it will costs them a million dollars of compute and if you add three more digits, it would costs them a billion dollars.
They will store encrypted files for decades though and in 30 years it might be much cheaper for them to decrypt them. That could still cause you trouble. That’s why you need a lot more digits to be safe,
Whats with the color code? I think once it goes past 100 year to crack, it should already be green.
It’s a little odd to me that cells for billions of years are yellow…surely if it would take a hacker a billion years to crack your password then it’s pretty darn safe.
Ok, so I’m good for couple hundred years but then I really need to hurry and change my password.
[deleted]
What people don’t seem to get about password cracking that id like to shine light on.
The issue isn’t about brute forcing your password by trying to sign into a website a million times. Most websites have some sort of rate limiting control.
The issue is when you reuse the same password literally everywhere, and that crappy AI vibe coded store or game site gets hacked. Then they crack the hashes they found there, associate your email with that password, and then use that pair on every service on the internet.
Also, simple substitutions are less secure than you think. Very simple example, but password and p@ssword are not too far off from each other in terms of crackability due to the way a lot of hackers run their cracking. It’s still better, but I wouldn’t follow the chart 1 to 1 with a substitution like that.
Another thing, is id personally be careful with passphrases getting bigger. For now, passphrases are extremely secure. Using a couple words with a symbol separator (e.g. pertinent-obsolete-cat or orange-three-year) makes a password that is very long and easy to remember. I highly recommend adding a random symbol or number into the password somewhere. As crackers haven’t caught up to my knowledge yet, but once they wisen up and password managers continue to go mainstream i absolutely could see them brute forcing for words instead of individual characters
Sure is awesome that the password requirements at work are such that it’s 3b years of brute force required, but I still have to change it every 3 months.
Doesn’t this assume that hacker knows the password length and type? That is, unlike movies, you’re not hacking 1 character at a time and “locking it in”. You could try every combination of 16 alphanumerics and symbols, and never be able to guess my 4 numeral code. It’s not like the hash gives you clues as to the length or contents.
Still not a fan of the Layout. It to me looks much that the passwords need more character in the string. But it would be much better to push people for longer passwords, because that leads to harder passwords that are also better to remember than some finger breaking letter salad.
Or in mathematical terms, the amount of the characters is the base while the length is the exponent. And increasing the latter makes a much bigger space of combinations 🙂
It’s faster to just wait for reliable quantum computers than brute forcing billion of years 🫣
alao, reminder that you can just use passphrases people. 3-5 random words, number in some place (before or after one word)
Banana6-Telephone-Plastic-Elephant is easy-ish to remember and easy to type. D8;kt7z?BpP8 isn’t. The former still has more entropy, dict attacks don’t really work here
How do passphrases fit into this? Longer and mixing in a few uppercase letters, numbers and symbols but a good chunk still dictionary words. I still recall horse battery staple camel.
I like how 9bn years is yellow. Like it’s kind of iffy whether that amount of time is enough.
So if a hacker can take 33 000 years to break my password it’s considered orange level of safety ?
Brute force is almost never done. Far easier to social engineer or try passwords from previous leaks. Most people struggle with more than a few passwords. Not saying a secure password is a bad idea, just that this is highly unlikely to be the attack vector.
Getting some idiot in it to click a bad link and use a password that was stored for a person is far easier. Last pass got breached several years ago which is how some people stored passwords for unique per site. Which shows you that even that has risks.
How did you choose the hardware each year? Is it based on a set budget? If not, why not 32x5090s or a cluster of H100s?
I always hate this visualization, as folks try to find the shortest password complexity – then promptly either forget it because it’s too complex, or use the same password for all logins and get compromised regardless. And Joe Shmoe is far more likely to be targeted by social engineering or a password breach than anything else.
Using a long text string, like „redditisforsmartpeople“, makes for a password that is easier to memorize and remember, and more likely to use different passwords for different logins.
So bank card pins are the worst thing in the world?
I KNEW setting 111111111111111111 as my password was a good idea! 18 numbers, LET’S GOOOOO!!!
Kind of surprises me that even a numbers-only, 18 character password, would take 228k years. Surprised that isn’t also “instantly” or hours. Why is that?