I updated our popular password chart for 2024 with more data!

45 Comments

  1. hivesystems

    Hi everyone – I’m back again with the 2024 update to our password table! Computers, and GPUs in particular, are getting faster (looking at you OpenAI), but password hash algorithm options are also getting better (for now…). This table outlines the time it takes a computer to brute force your password, and isn’t indicative of how fast a hacker can break your password – especially if they stole your password via phishing, or you reuse your passwords (shame!). It’s a good visual to show people why better passwords can lead to better cybersecurity – but ultimately it’s just one of many tools we can use to talk about protecting ourselves online!

  2. MartyrKomplx-Prime

    Eleven thousand years for an 18 digit number?

  3. I am not sure what methodology was used, but aren’t these just calculated numbers based numbers based on the assumption that the hacker already has information about the password.

    I am not a cryptologist, but my assumption would be that an attacker would first employ a dictionary attack, before trying to brute force in some sensible manner.

    Realistically if you had a a password that consisted of 13 random numbers, would a hacker really attempt to bruteforce combinations of 13 random numbers rather than any combination of letters and numbers. I’d guess that a long number only password is so unusual that an smart brute force algorithm would try its luck with shorter combined number/letter passwords before trying to just guess insanely long combination of random numbers.

    Again I am just a software developer and not particularly informed but my intuition tells me that you’d crack an 8 characters upper+lower+number PW faster than a combination of 14 numbers, simply because in a real world scenario it doesn’t seem sensible for hacker to target the latter.

  4. HorserorOfHorsekind

    good luck breaking my eXpLode!PurPLe4NiPPle5

  5. MemeBirthGiver

    There is nobody on earth willing to keep 10 4090’s running more than 1 hour to crack your password

  6. SirVeras

    We have the table from 2022 in our office hanging and comparing there two seems like the hackers got worse over the years? Only 4x instantly as in 2022 has like 22x instantly. Can you clarify?

    EDIT: read your detailed blog on your website. I guess the difference is the used hash for the password. Until this year it was MD5 and this year its bcrypt.

  7. Fantastic-Shopping10

    Lol. Why are passwords that take thousands or millions of years to crack shaded orange or yellow? Seems pretty safe to me.

  8. foamingdogfever

    Makes me glad I use Argon2id with 4GB memory requirement, 4 threads, 45s iteration time, and 32-character passwords generated by OpenSSL.

  9. BanMeYouFascist

    Meh. That’s what 2FA is for. My passwords are probably fairly shitty but I have 2FA on everything important.

  10. DrMorphling

    So I changed my password few years back from 3 years to hack to 164m? Tho i reuse my password in many unimportant things.

  11. AMechanicum

    Make unbreakable password.

    Data leak next day.

  12. bobbster574

    Gotta love how the green section starts at like 10 billion years.

    You’re safe for now, but you never know who will have cracked your password given a measly 479 years 🙃

  13. Alive-Ad-1845

    my school email password is “FortniteBattlepass04!”

  14. Flying-T

    Why are 2 years and 89.000 years in the same color bracket lol

  15. I dunno. Seems to me my alphabet only u/l case only 11 character pw takes 89k years to break. Seems pretty secure to me. Even if they managed to break it in 1/4 of that time, anything in my email is gonna be irrelevent. At that point, they can have my bank pw, my Apple pin. None if it is gonna matter in 20k years. Prolly sooner than that once the war starts that out gov seems hell bent on getting us in anyway.

  16. David0ne86

    I like how they have not put in green even something like 33k years lmao.

  17. AnywhereHorrorX

    This is why you need to play the Password game.

    [https://neal.fun/password-game/](https://neal.fun/password-game/)

    That will teach you all you need to know about ultimate uncrackable password requirements.

  18. agouraki

    how long would it take to “Crack” the password that Data says on Star trek?

  19. It’s fun to look at the past tables and see the difference, but it would be really cool to see the tables side by side, to see how the time to crack would change year over year, regardless of the difference in GPUs and what not.

  20. tarkology

    use keepassxc on your desktop, encrypt your disk, install keepassium on your iphone and randomize every password you have, enable auto sign in firefox, btw use firefox

  21. SgtMoose42

    All lowercase letters is perfectly fine if it’s long enough it’s much easier to type and remember.

    My current password is 17 letters long. It has 1 capital 1 number and 1 special character because it’s required by my orgs password policy.

    We really just need to change the name from “Password” to “Passphrase” and people will accept typing in longer passwords.

    correcthorsebatterystaple no this is not my password.

    I always wonder about these types of attacks, most passwords will lock the user out after too many failed attempts.

  22. First-Junket124

    So from closely inspecting this table I have deduced that passwords with 1-3 characters or more than 18 characters are impenetrable as they are not on this table.

    Thank you OP I will now change my passwords to 2 characters for ease of use AND security, couldn’t have done this without you.

  23. I use a really strong password on my password manager, but how many passwords should I save in my password manager? When is it too many and too dangerous to keep them in there?

  24. binky779

    Realistically tho. If you have these kinds of resources you arent dedicating them to cracking one single user.

    How many users might a hacker try to brute force at the same time? How will that affect the time?

    Given that the resources are better used when you know there is something worth stealing, what is the chance of an average, not high-value, user getting their password brute forced?

  25. omenmedia

    This makes me feel real smug for using random mixed case + number + symbol 20 char passwords for everything.

  26. ChickenPijja

    So you’re saying if I used my credit card number(which realistically is the only number I’d be able to remember 16 digits of) it would take 119 years, but P4$$word only takes 7 years? I think I’d stick with P4$$word as it’s far easier to remember, and if I had to change it because it got compromised it’s easier to change to Pas$w0rd but just as quick to crack

  27. Meatslinger

    The green zone in the middle column is the one to take note of; you can have simple, easily memorable passwords that are secure simply by being long. My company has transitioned to pass “phrases” with spaces included because it’s arguably more secure than the old “8 characters, mix of letters, numbers, symbols, and hieroglyphics” trope, and is far less likely to be written on a sticky note. When you give someone a password like “6$fxY3@u”, they’re gonna write it down somewhere and introduce a new risk as a result. When you tell them their pass phrase is “Functional Barista Treasure”, it’s probably already locked in before they’ve even used it for the first time.

    (Obviously IT shouldn’t be telling people what their password is going to be – it should be set by the user – but this is just an example for the sake of argument)

  28. basically_an_opinion

    but how they can brut force if you get access denied after 5 attempts

  29. Addicted2Trance

    Bitwarden made my internet experience much easier, and safer.

  30. Brynjar-Spear111

    Im@g1n3 @ p@@$$ w0rd a$ str0ng as th1s

    Over 100 bits of entropy.

  31. ChaosSlave51

    All these numbers assume direct access to the encrypted data. In 99% of cases the hacker has to go though a portal that will only give them 3 or 5 tries before significantly throttling them

  32. Escapement_Watch

    For all my important things I don’t even know my own passwords.

    I use a password program that does 25 character random passwords

  33. KeycapS_

    7 years, not that bad I guess. No one will want to run 12×4090 for 7 years to get my data 😀

  34. CXC_Opexyc

    — WHAT will you have after 500 hundred years?!

    — Your password, dad… I’ll have your password…

  35. JonseyMcFly

    So, 9 Characters upper and lowercase is the sweet spot.

  36. CXC_Opexyc

    Dumbass question, but how exactly does bruteforcing work? Don’t most services say “fu” after like 3 failed tries?

  37. BasisZock

    Why did it increase from last years so much? Was there an alphabet update I didn’t notice?

  38. PapaFlexing

    Work got ahold of one of these charts…. We’re now required to make a 15 character password with letters, numbers, and special characters oh ya, can’t forget the capital also.

    Gosh it’s so dumb

  39. Testaccount-1-

    Man this makes me feel stupid for having 100 character passwords

  40. jedigras

    Why cant they make a chart that takes into consideration the growth in processing power? we can’t crack a 18 character password before 19qn years… I think we did something wrong.

  41. RepeatWolf

    Password123! Has never looked so strong!

    PS. I do not use or advocate the use of this password

  42. StrictLimitForever

    Can we please stop with passwords already? Just give us some highly secure physical 2FA authentication device for EVERYTHING.

  43. PhuckWar

    My password is “1111111111111111” so good luck wasting 119 years

Write A Comment