Hi everyone – I’m back again with the 2024 update to our password table! Computers, and GPUs in particular, are getting faster (looking at you OpenAI), but password hash algorithm options are also getting better (for now…). This table outlines the time it takes a computer to brute force your password, and isn’t indicative of how fast a hacker can break your password – especially if they stole your password via phishing, or you reuse your passwords (shame!). It’s a good visual to show people why better passwords can lead to better cybersecurity – but ultimately it’s just one of many tools we can use to talk about protecting ourselves online!
MartyrKomplx-Prime
Eleven thousand years for an 18 digit number?
Yankas
I am not sure what methodology was used, but aren’t these just calculated numbers based numbers based on the assumption that the hacker already has information about the password.
I am not a cryptologist, but my assumption would be that an attacker would first employ a dictionary attack, before trying to brute force in some sensible manner.
Realistically if you had a a password that consisted of 13 random numbers, would a hacker really attempt to bruteforce combinations of 13 random numbers rather than any combination of letters and numbers. I’d guess that a long number only password is so unusual that an smart brute force algorithm would try its luck with shorter combined number/letter passwords before trying to just guess insanely long combination of random numbers.
Again I am just a software developer and not particularly informed but my intuition tells me that you’d crack an 8 characters upper+lower+number PW faster than a combination of 14 numbers, simply because in a real world scenario it doesn’t seem sensible for hacker to target the latter.
HorserorOfHorsekind
good luck breaking my eXpLode!PurPLe4NiPPle5
MemeBirthGiver
There is nobody on earth willing to keep 10 4090’s running more than 1 hour to crack your password
SirVeras
We have the table from 2022 in our office hanging and comparing there two seems like the hackers got worse over the years? Only 4x instantly as in 2022 has like 22x instantly. Can you clarify?
EDIT: read your detailed blog on your website. I guess the difference is the used hash for the password. Until this year it was MD5 and this year its bcrypt.
Fantastic-Shopping10
Lol. Why are passwords that take thousands or millions of years to crack shaded orange or yellow? Seems pretty safe to me.
foamingdogfever
Makes me glad I use Argon2id with 4GB memory requirement, 4 threads, 45s iteration time, and 32-character passwords generated by OpenSSL.
BanMeYouFascist
Meh. That’s what 2FA is for. My passwords are probably fairly shitty but I have 2FA on everything important.
DrMorphling
So I changed my password few years back from 3 years to hack to 164m? Tho i reuse my password in many unimportant things.
AMechanicum
Make unbreakable password.
Data leak next day.
bobbster574
Gotta love how the green section starts at like 10 billion years.
You’re safe for now, but you never know who will have cracked your password given a measly 479 years 🙃
Alive-Ad-1845
my school email password is “FortniteBattlepass04!”
Flying-T
Why are 2 years and 89.000 years in the same color bracket lol
xxdibxx
I dunno. Seems to me my alphabet only u/l case only 11 character pw takes 89k years to break. Seems pretty secure to me. Even if they managed to break it in 1/4 of that time, anything in my email is gonna be irrelevent. At that point, they can have my bank pw, my Apple pin. None if it is gonna matter in 20k years. Prolly sooner than that once the war starts that out gov seems hell bent on getting us in anyway.
David0ne86
I like how they have not put in green even something like 33k years lmao.
That will teach you all you need to know about ultimate uncrackable password requirements.
agouraki
how long would it take to “Crack” the password that Data says on Star trek?
DeathstrackReal
Oh cool 3qd years
clevor1
It’s fun to look at the past tables and see the difference, but it would be really cool to see the tables side by side, to see how the time to crack would change year over year, regardless of the difference in GPUs and what not.
tarkology
use keepassxc on your desktop, encrypt your disk, install keepassium on your iphone and randomize every password you have, enable auto sign in firefox, btw use firefox
SgtMoose42
All lowercase letters is perfectly fine if it’s long enough it’s much easier to type and remember.
My current password is 17 letters long. It has 1 capital 1 number and 1 special character because it’s required by my orgs password policy.
We really just need to change the name from “Password” to “Passphrase” and people will accept typing in longer passwords.
correcthorsebatterystaple no this is not my password.
I always wonder about these types of attacks, most passwords will lock the user out after too many failed attempts.
First-Junket124
So from closely inspecting this table I have deduced that passwords with 1-3 characters or more than 18 characters are impenetrable as they are not on this table.
Thank you OP I will now change my passwords to 2 characters for ease of use AND security, couldn’t have done this without you.
00sra
I use a really strong password on my password manager, but how many passwords should I save in my password manager? When is it too many and too dangerous to keep them in there?
Loud-Comparison7859
So 2m years
binky779
Realistically tho. If you have these kinds of resources you arent dedicating them to cracking one single user.
How many users might a hacker try to brute force at the same time? How will that affect the time?
Given that the resources are better used when you know there is something worth stealing, what is the chance of an average, not high-value, user getting their password brute forced?
omenmedia
This makes me feel real smug for using random mixed case + number + symbol 20 char passwords for everything.
ChickenPijja
So you’re saying if I used my credit card number(which realistically is the only number I’d be able to remember 16 digits of) it would take 119 years, but P4$$word only takes 7 years? I think I’d stick with P4$$word as it’s far easier to remember, and if I had to change it because it got compromised it’s easier to change to Pas$w0rd but just as quick to crack
Meatslinger
The green zone in the middle column is the one to take note of; you can have simple, easily memorable passwords that are secure simply by being long. My company has transitioned to pass “phrases” with spaces included because it’s arguably more secure than the old “8 characters, mix of letters, numbers, symbols, and hieroglyphics” trope, and is far less likely to be written on a sticky note. When you give someone a password like “6$fxY3@u”, they’re gonna write it down somewhere and introduce a new risk as a result. When you tell them their pass phrase is “Functional Barista Treasure”, it’s probably already locked in before they’ve even used it for the first time.
(Obviously IT shouldn’t be telling people what their password is going to be – it should be set by the user – but this is just an example for the sake of argument)
basically_an_opinion
but how they can brut force if you get access denied after 5 attempts
Addicted2Trance
Bitwarden made my internet experience much easier, and safer.
Brynjar-Spear111
Im@g1n3 @ p@@$$ w0rd a$ str0ng as th1s
Over 100 bits of entropy.
ChaosSlave51
All these numbers assume direct access to the encrypted data. In 99% of cases the hacker has to go though a portal that will only give them 3 or 5 tries before significantly throttling them
Escapement_Watch
For all my important things I don’t even know my own passwords.
I use a password program that does 25 character random passwords
KeycapS_
7 years, not that bad I guess. No one will want to run 12×4090 for 7 years to get my data 😀
CXC_Opexyc
— WHAT will you have after 500 hundred years?!
— Your password, dad… I’ll have your password…
JonseyMcFly
So, 9 Characters upper and lowercase is the sweet spot.
CXC_Opexyc
Dumbass question, but how exactly does bruteforcing work? Don’t most services say “fu” after like 3 failed tries?
BasisZock
Why did it increase from last years so much? Was there an alphabet update I didn’t notice?
PapaFlexing
Work got ahold of one of these charts…. We’re now required to make a 15 character password with letters, numbers, and special characters oh ya, can’t forget the capital also.
Gosh it’s so dumb
Testaccount-1-
Man this makes me feel stupid for having 100 character passwords
jedigras
Why cant they make a chart that takes into consideration the growth in processing power? we can’t crack a 18 character password before 19qn years… I think we did something wrong.
RepeatWolf
Password123! Has never looked so strong!
PS. I do not use or advocate the use of this password
StrictLimitForever
Can we please stop with passwords already? Just give us some highly secure physical 2FA authentication device for EVERYTHING.
PhuckWar
My password is “1111111111111111” so good luck wasting 119 years
45 Comments
Hi everyone – I’m back again with the 2024 update to our password table! Computers, and GPUs in particular, are getting faster (looking at you OpenAI), but password hash algorithm options are also getting better (for now…). This table outlines the time it takes a computer to brute force your password, and isn’t indicative of how fast a hacker can break your password – especially if they stole your password via phishing, or you reuse your passwords (shame!). It’s a good visual to show people why better passwords can lead to better cybersecurity – but ultimately it’s just one of many tools we can use to talk about protecting ourselves online!
Eleven thousand years for an 18 digit number?
I am not sure what methodology was used, but aren’t these just calculated numbers based numbers based on the assumption that the hacker already has information about the password.
I am not a cryptologist, but my assumption would be that an attacker would first employ a dictionary attack, before trying to brute force in some sensible manner.
Realistically if you had a a password that consisted of 13 random numbers, would a hacker really attempt to bruteforce combinations of 13 random numbers rather than any combination of letters and numbers. I’d guess that a long number only password is so unusual that an smart brute force algorithm would try its luck with shorter combined number/letter passwords before trying to just guess insanely long combination of random numbers.
Again I am just a software developer and not particularly informed but my intuition tells me that you’d crack an 8 characters upper+lower+number PW faster than a combination of 14 numbers, simply because in a real world scenario it doesn’t seem sensible for hacker to target the latter.
good luck breaking my eXpLode!PurPLe4NiPPle5
There is nobody on earth willing to keep 10 4090’s running more than 1 hour to crack your password
We have the table from 2022 in our office hanging and comparing there two seems like the hackers got worse over the years? Only 4x instantly as in 2022 has like 22x instantly. Can you clarify?
EDIT: read your detailed blog on your website. I guess the difference is the used hash for the password. Until this year it was MD5 and this year its bcrypt.
Lol. Why are passwords that take thousands or millions of years to crack shaded orange or yellow? Seems pretty safe to me.
Makes me glad I use Argon2id with 4GB memory requirement, 4 threads, 45s iteration time, and 32-character passwords generated by OpenSSL.
Meh. That’s what 2FA is for. My passwords are probably fairly shitty but I have 2FA on everything important.
So I changed my password few years back from 3 years to hack to 164m? Tho i reuse my password in many unimportant things.
Make unbreakable password.
Data leak next day.
Gotta love how the green section starts at like 10 billion years.
You’re safe for now, but you never know who will have cracked your password given a measly 479 years 🙃
my school email password is “FortniteBattlepass04!”
Why are 2 years and 89.000 years in the same color bracket lol
I dunno. Seems to me my alphabet only u/l case only 11 character pw takes 89k years to break. Seems pretty secure to me. Even if they managed to break it in 1/4 of that time, anything in my email is gonna be irrelevent. At that point, they can have my bank pw, my Apple pin. None if it is gonna matter in 20k years. Prolly sooner than that once the war starts that out gov seems hell bent on getting us in anyway.
I like how they have not put in green even something like 33k years lmao.
This is why you need to play the Password game.
[https://neal.fun/password-game/](https://neal.fun/password-game/)
That will teach you all you need to know about ultimate uncrackable password requirements.
how long would it take to “Crack” the password that Data says on Star trek?
Oh cool 3qd years
It’s fun to look at the past tables and see the difference, but it would be really cool to see the tables side by side, to see how the time to crack would change year over year, regardless of the difference in GPUs and what not.
use keepassxc on your desktop, encrypt your disk, install keepassium on your iphone and randomize every password you have, enable auto sign in firefox, btw use firefox
All lowercase letters is perfectly fine if it’s long enough it’s much easier to type and remember.
My current password is 17 letters long. It has 1 capital 1 number and 1 special character because it’s required by my orgs password policy.
We really just need to change the name from “Password” to “Passphrase” and people will accept typing in longer passwords.
correcthorsebatterystaple no this is not my password.
I always wonder about these types of attacks, most passwords will lock the user out after too many failed attempts.
So from closely inspecting this table I have deduced that passwords with 1-3 characters or more than 18 characters are impenetrable as they are not on this table.
Thank you OP I will now change my passwords to 2 characters for ease of use AND security, couldn’t have done this without you.
I use a really strong password on my password manager, but how many passwords should I save in my password manager? When is it too many and too dangerous to keep them in there?
So 2m years
Realistically tho. If you have these kinds of resources you arent dedicating them to cracking one single user.
How many users might a hacker try to brute force at the same time? How will that affect the time?
Given that the resources are better used when you know there is something worth stealing, what is the chance of an average, not high-value, user getting their password brute forced?
This makes me feel real smug for using random mixed case + number + symbol 20 char passwords for everything.
So you’re saying if I used my credit card number(which realistically is the only number I’d be able to remember 16 digits of) it would take 119 years, but P4$$word only takes 7 years? I think I’d stick with P4$$word as it’s far easier to remember, and if I had to change it because it got compromised it’s easier to change to Pas$w0rd but just as quick to crack
The green zone in the middle column is the one to take note of; you can have simple, easily memorable passwords that are secure simply by being long. My company has transitioned to pass “phrases” with spaces included because it’s arguably more secure than the old “8 characters, mix of letters, numbers, symbols, and hieroglyphics” trope, and is far less likely to be written on a sticky note. When you give someone a password like “6$fxY3@u”, they’re gonna write it down somewhere and introduce a new risk as a result. When you tell them their pass phrase is “Functional Barista Treasure”, it’s probably already locked in before they’ve even used it for the first time.
(Obviously IT shouldn’t be telling people what their password is going to be – it should be set by the user – but this is just an example for the sake of argument)
but how they can brut force if you get access denied after 5 attempts
Bitwarden made my internet experience much easier, and safer.
Im@g1n3 @ p@@$$ w0rd a$ str0ng as th1s
Over 100 bits of entropy.
All these numbers assume direct access to the encrypted data. In 99% of cases the hacker has to go though a portal that will only give them 3 or 5 tries before significantly throttling them
For all my important things I don’t even know my own passwords.
I use a password program that does 25 character random passwords
7 years, not that bad I guess. No one will want to run 12×4090 for 7 years to get my data 😀
— WHAT will you have after 500 hundred years?!
— Your password, dad… I’ll have your password…
So, 9 Characters upper and lowercase is the sweet spot.
Dumbass question, but how exactly does bruteforcing work? Don’t most services say “fu” after like 3 failed tries?
Why did it increase from last years so much? Was there an alphabet update I didn’t notice?
Work got ahold of one of these charts…. We’re now required to make a 15 character password with letters, numbers, and special characters oh ya, can’t forget the capital also.
Gosh it’s so dumb
Man this makes me feel stupid for having 100 character passwords
Why cant they make a chart that takes into consideration the growth in processing power? we can’t crack a 18 character password before 19qn years… I think we did something wrong.
Password123! Has never looked so strong!
PS. I do not use or advocate the use of this password
Can we please stop with passwords already? Just give us some highly secure physical 2FA authentication device for EVERYTHING.
My password is “1111111111111111” so good luck wasting 119 years