Whilst browsing through some forums today a user sent me a link: http://www.lockdown.co.uk/?pg=combi&s=articles, this article is all about how secure is your password, and how long it takes to crack.
This article hs been released under the Creative Commons Licence and was created by Ivan Lucas from www.lockdown.co.uk. The full article is posted below. Please feel free to share or distribute this article under the Creative Commons licence.
Password Recovery Speeds
This document shows the approximate amount of time required for a computer or a cluster of computers to guess various passwords. The figures shown are approximate and are the maximum time required to guess each password using a simple brute force “key-search” attack, it may (and probably will) be possible to guess correctly without trying all the combinations shown using other methods of attack or by having a “lucky guess”.
See the bottom of the page for details about the classes of attack.
10 Characters
Just numbers. As you can see choosing a password from such a small range of characters is a bad idea.
| Numerals | 0123456789 | ||||||
|---|---|---|---|---|---|---|---|
| Password | Class of Attack | ||||||
| Length | Combinations | Class A | Class B | Class C | Class D | Class E | Class F |
| 2 | 100 | Instant | Instant | Instant | Instant | Instant | Instant |
| 3 | 1000 | Instant | Instant | Instant | Instant | Instant | Instant |
| 4 | 10,000 | Instant | Instant | Instant | Instant | Instant | Instant |
| 5 | 100,000 | 10 Secs | Instant | Instant | Instant | Instant | Instant |
| 6 | 1 Million | 1½ Mins | 10 Seconds | Instant | Instant | Instant | Instant |
| 7 | 10 Million | 17 Mins | 1½ Mins | 1½ Mins | Instant | Instant | Instant |
| 8 | 100 Million | 2¾ Hours | 17 Mins | 1½ Mins | 10 Seconds | Instant | Instant |
| 9 | 1000 Million | 28 Hours | 2¾ Hours | 17 Mins | 1½ Mins | 10 Seconds | Instant |
26 Characters
The full alphabet, either upper or lower case (not both in this case).
| Upper Case Alpha | ABCDEFGHIJKLMNOPQRSTUVWXYZ | ||||||
|---|---|---|---|---|---|---|---|
| Lower Case Alpha | abcdefghijklmnopqrstuvwxyz | ||||||
| Password | Class of Attack | ||||||
| Length | Combinations | Class A | Class B | Class C | Class D | Class E | Class F |
| 2 | 676 | Instant | Instant | Instant | Instant | Instant | Instant |
| 3 | 17,576 | < 2 Secs | Instant | Instant | Instant | Instant | Instant |
| 4 | 456,976 | 46 Secs | 5 Secs | Instant | Instant | Instant | Instant |
| 5 | 11.8 Million | 20 Mins | 2 Mins | 12 Secs | Instant | Instant | Instant |
| 6 | 308.9 Million | 8½ Hours | 51½ Mins | 5 Mins | 30 Secs | 3 Secs | Instant |
| 7 | 8 Billion | 9 Days | 22 Hours | 2¼ Hours | 13 Mins | 1¼ Mins | 8 Secs |
| 8 | 200 Billion | 242 Days | 24 Days | 2½ Days | 348 Mins | 35 Mins | 3½ Mins |
| 9 | 5.4 Trillion | 17 Years | 21 Months | 63 Days | 6¼ Days | 15 Hours | 1½ Hours |
| 10 | 141 Trillion | 447 Years | 45 Years | 4½ Years | 163 Days | 16 Days | 39¼ Hours |
| 12 | 95 Quadrillion | 302,603 Years | 30,260 Years | 3,026 Years | 302 Years | 30 Years | 3 Years |
| 15 | 1.6 Sextillion | 53 Trillion years | 532 Million years | 53 Million years | 5 Million years | 531,855 Years | 53,185 Years |
| 20 | 19.9 Octillion | 63 Quadrillion years | 6.3 Quadrillion years | 631 Trillion years | 63.1 Trillion years | 6.3 Trillion years | 631 Billion years |
36 Characters
The full alphabet, either upper or lower case (not both in this case) plus numbers.
| Upper Case Alpha | ABCDEFGHIJKLMNOPQRSTUVWXYZ | ||||||
|---|---|---|---|---|---|---|---|
| Lower Case Alpha | abcdefghijklmnopqrstuvwxyz | ||||||
| Numerals | 0123456789 | ||||||
| Password | Class of Attack | ||||||
| Length | Combinations | Class A | Class B | Class C | Class D | Class E | Class F |
| 2 | 1,296 | Instant | Instant | Instant | Instant | Instant | Instant |
| 3 | 46,656 | 4 Secs | Instant | Instant | Instant | Instant | Instant |
| 4 | 1.6 million | 2½ Mins | 16 Seconds | 1½ Seconds | Instant | Instant | Instant |
| 5 | 60.4 million | 1½ Hours | 10 Mins | 1 Min | Instant | Instant | Instant |
52 Characters
This time we’re trying the full alphabet but using a mixture of upper and lower case letters, that effectively doubles the number of combinations when compared with just using a single case.
| Mixed Alpha | AaBbCcDdEeFfGgHhIiJjKkLlMmNnOoPpQqRrSsTtUuVvWwXxYyZz | ||||||
|---|---|---|---|---|---|---|---|
| Password | Class of Attack | ||||||
| Length | Combinations | Class A | Class B | Class C | Class D | Class E | Class F |
| 2 | 2,704 | Instant | Instant | Instant | Instant | Instant | Instant |
| 3 | 140,608 | 14 Secs | < 2 Secs | Instant | Instant | Instant | Instant |
| 4 | 7.3 Million | 12½ Mins | 1¼ Mins | 8 Secs | Instant | Instant | Instant |
| 5 | 380 Million | 10½ Hours | 1 Hour | 6 Minutes | 38 Secs | 4 Secs | Instant |
| 6 | 19 Billion | 23 Days | 2¼ Days | 5½ Hours | 33 Mins | 3¼ Mins | 19 Secs |
| 7 | 1 Trillion | 3¼ Years | 119 Days | 12 Days | 28½ Hours | 3 Hours | 17 Mins |
| 8 | 53 Trillion | 169½ Years | 17 Years | 1½ Years | 62 Days | 6 Days | 15 Hours |
| 9 | 2.7 Quadrillion | 8,815 Years | 881 Years | 88 Years | 9 Years | 322 Days | 32 Days |
62 Characters
Mixed upper and lower case alphabetic characters plus numbers.
| Mixed Alpha and Numerals | 0123456789AaBbCcDdEeFfGgHhIiJjKkLlMmNnOoPpQqRrSsTtUuVvWwXxYyZz | ||||||
|---|---|---|---|---|---|---|---|
| Password | Class of Attack | ||||||
| Length | Combinations | Class A | Class B | Class C | Class D | Class E | Class F |
| 2 | 3,844 | Instant | Instant | Instant | Instant | Instant | Instant |
| 3 | 238,328 | 23 Secs | < 3 Secs | Instant | Instant | Instant | Instant |
| 4 | 15 Million | 24½ Mins | 2½ Mins | 15 Secs | < 2 Secs | Instant | Instant |
| 5 | 916 Million | 1 Day | 2½ Hours | 15¼ Mins | 1½ Mins | 9 Secs | Instant |
| 6 | 57 Billion | 66 Days | 6½ Days | 16 Hours | 1½ Hours | 9½ Mins | 56 Secs |
| 7 | 3.5 Trillion | 11 Years | 1 Year | 41 Days | 4 Days | 10 Hours | 58 Mins |
| 8 | 218 Trillion | 692 Years | 69¼ Years | 7 Years | 253 Days | 25¼ Days | 60½ Hours |
86 Characters
Mixed upper and lower case alphabet and common symbols.
| Mixed Alpha & Symbols | AaBbCcDdEeFfGgHhIiJjKkLlMmNnOoPpQqRrSsTtUuVvWwXxYyZz <SP>!”#$%&’()*+,-./:;<=>?@[\]^_`{|}~ | ||||||
|---|---|---|---|---|---|---|---|
| Password | Class of Attack | ||||||
| Length | Combinations | Class A | Class B | Class C | Class D | Class E | Class F |
| 2 | 7,396 | Instant | Instant | Instant | Instant | Instant | Instant |
| 8 | 2.9 Quadrillion | 9,488 Years | 948 Years | 94 Years | 57 Years | 346 Days | 34 Days |
96 Characters
Mixed upper and lower case alphabet plus numbers and common symbols.
| Mixed Alpha, Numerals & Symbols | 0123456789AaBbCcDdEeFfGgHhIiJjKkLlMmNnOoPpQqRrSsTtUuVvWwXxYyZz <SP>!”#$%&’()*+,-./:;<=>?@[\]^_`{|}~ | ||||||
|---|---|---|---|---|---|---|---|
| Password | Class of Attack | ||||||
| Length | Combinations | Class A | Class B | Class C | Class D | Class E | Class F |
| 2 | 9,216 | Instant | Instant | Instant | Instant | Instant | Instant |
| 3 | 884,736 | 88½ Secs | 9 Secs | Instant | Instant | Instant | Instant |
| 4 | 85 Million | 2¼ Hours | 14 Mins | 1½ Mins | 8½ Secs | Instant | Instant |
| 5 | 8 Billion | 9½ Days | 22½ Hours | 2¼ Hours | 13½ Mins | 1¼ Mins | 8 Secs |
| 6 | 782 Billion | 2½ Years | 90 Days | 9 Days | 22 Hours | 2 Hours | 13 Mins |
| 7 | 75 Trillion | 238 Years | 24 Years | 2½ Years | 87 Days | 8½ Days | 20 Hours |
| 8 | 7.2 Quadrillion | 22,875 Years | 2,287 Years | 229 Years | 23 Years | 2¼ Years | 83½ Days |
Examples
These are just a couple of examples to show the resilience of certain types of password, using the information in the tables above you will be able to make your own examples.
| Sample Passwords | Class of Attack | ||||||
|---|---|---|---|---|---|---|---|
| Pwd | Combinations | Class A | Class B | Class C | Class D | Class E | Class F |
| darren | 308.9 Million | 8½ Hours | 51½ Mins | 5 Mins | 30 Secs | 3 Secs | Instant |
| Land3rz | 3.5 Trillion | 11 Years | 1 Year | 41 Days | 4 Days | 10 Hours | 58 Mins |
| B33r&Mug | 7.2 Quadrillion | 22,875 Years | 2,287 Years | 229 Years | 23 Years | 2¼ Years | 83½ Days |
Classes of Attack
These are just some example speeds, I’d be interested to hear from people with more information about the speed taken to crack various types of passwords with various hardware.
A. 10,000 Passwords/sec
Typical for recovery of Microsoft Office passwords on a Pentium 100
B. 100,000 Passwords/sec
Typical for recovery of Windows Password Cache (.PWL Files) passwords on a Pentium 100
C. 1,000,000 Passwords/sec
Typical for recovery of ZIP or ARJ passwords on a Pentium 100
D. 10,000,000 Passwords/sec
Fast PC, Dual Processor PC.
E. 100,000,000 Passwords/sec
Workstation, or multiple PC’s working together.
F. 1,000,000,000 Passwords/sec
Typical for medium to large scale distributed computing, Supercomputers.
Distributed.net’s Project Bovine RC5-64 possibly the fastest computer on earth has recently reached a speed of 76.1 Billion passwords per second!
We have now finished the FATE DVD and sent out a copy to all artists that participated. For those that would like to see the DVD you can view it online at: http://video.concepts.org.uk/displayimage.php?pos=-20
This video will soon be made available on our Art site and the FATE website. Please feel free to leave any feedback on the video and we hope you enjoy viewing the wonderful art on show.
So I’ve been crawling the net all day, checking Directories and Search Engines to see if any of our sites are listed. If they aren’t then I’ll spend a few minutes on each site submitting my site.
So why do I bother and why should you bother? Well the simple answer is “PROMOTION”, not all our visitors use Google or Yahoo to find our site so it is an important factor for me to drive traffic to my site from any resource I can (this also includes Social Networking sites).
Do I pay for submitting URLs? No, there are so many free resources out there, that currently I will only use free sites. However in the future, depending on the worth, I may pay to get a listing on another site.
So as part of our tutorials I am going to share with you a list of free Directories and Search Engines that will allow you to list your site. There is absolutely hundreds of free sites so this is not a complete list, but I will update the list as I add my site to the directories.
Directories and Search Engines:
- www.freeindex.co.uk
- www.wwwi.co.uk
- www.canlinks.net
- www.qango.com
- www.geniusfind.com
- www.webworldindex.com
- www.scrubtheweb.com
Not Tested Yet:
- www.exactseek.com
- www.gigablast.com
- www.infotiger.com
- www.entireweb.com
- www.goguides.org
- www.walhello.com
- www.useroo.com
- www.submitservices.com
- www.steam.com
- www.knowbe.com
- www.joeant.com
- www.jayde.com
- www.gimpsy.com
Important Notes:
Some of these sites require you to create an account so keep a note of your login details. The best way to keep track of these sites is to have a small database, and keep track of your listing, login details, etc. Keep checking back as I’ll be updating the list.
For those that are unaware of FATE (Fife Artists Together Enterprises), it is a social partnership between Concepts & Crystal Galleries which aims to provide opportunities for artists to exhibit with their global counterparts. All work by FATE is completely voluntary, not for profit, and doesn’t rely on donations or funding.
Recently FATE launched an exhibition at the Rothes Halls in Glenrothes, Fife, which showcased talent from America, Scotland, Czech Republic, and Russia (the full artist list can be viewed at the official FATE site: www.fifeart.org.uk).
- blue by Teresa Maria
- Lady of Silenced Prince by Jarmila Hrubcova
- Ogler by Lenka Molkova
- Untitled by Stepan Mleczko
As part of the promotion package we have provided the artists, we also captured the setting up of the exhibition on DVD. We have now finished the DVD which is currently being sent out to all the artists involved.
Once all the artists have received their copy we will be showcasing the film online (details of where to view the film will be published shortly)
We would like to thank all the artists for taking part and helping contribute to an excellent and well recieved event. We wish you every success in the pursuit of your artistic career





