blog about this blog contact me  
 

How strong is your password?

 

After losing a bet to crack a Microsoft Word 2007 password I decided to launch a new website called HowStrongIsYourPassword.com.

Earlier versions of Microsoft Word, 97, 2000, and 2003 use a DES 40bit form of encryption which meant that a brute-force attack (which is to try all the possible combinations of passwords) meant that cracking the password was guaranteed.

However Word 2007 uses AES 128bit encryption, which makes the brute-force attack very very slow.  For example in tests on a Word 2003 passworded document I got upto 2,500,000 passwords per minute using 10 computers at once.  With the same hardware configuration I only got a mere 260 passwords per minute for a Word 2007 document. 

Well Done, Microsoft Office 2007 team, Bill Gates you should be proud!

After 5 days and 112 million tries I gave-up!

The length and complexity of your password can determine how secure it is:

 

Password is 6 characters long
94 possible characters in the password
26 uppercase + 26 lowercase + 32 special + 10 numbers = 94
946 = 689,869,781,056 unique password permutations
Need 133,076 password attempts/sec to attempt all combinations
(946/60 days (5184000 seconds) = 133,076)

Password is 7 characters long,
94 possible characters in the password
26 uppercase + 26 lowercase + 32 special + 10 numbers = 94
947 = 64,847,759,419,264 unique password permutations
Need 12,509,212 password attempts/sec to attempt all combinations
(947/60 days (5184000 seconds) = 12,509,212)

 
password-permutationspassword permutations
 

To summarise:

  • Make your password a long as possible
  • Use lower and uppercase, numbers and special symbols where appropriate.
  • Think of a short phrase and use that as your password.
  • Try your passwords at HowStrongIsYourPassword.com
 
 
Post Comment
Name:  
Email: (Will not be displayed)
URL:  
 
 
Understanding URLs, Web, Domain names, and TLDs
Posted: 23/04/2008 13:24:30
Comments (0)
How to Password Protect a Microsoft Office 97/2002/2003/2007 Document
Posted: 03/05/2008 17:12:14
Comments (0)
How strong is your password
Posted: 28/04/2008 23:34:05
Comments (0)
Different Data Destruction Methods
Posted: 03/05/2008 17:16:36
Comments (0)
ADSL Frequently Asked Questions
Posted: 24/09/2007 18:23:48
Comments (0)
Glossary of Wireless terms, Ad Hoc, MAC, Channel, Ethernet
Posted: 24/09/2007 18:16:03
Comments (0)
Gossary of DSL terms, Dynamic IP Address, Mbps
Posted: 24/09/2007 18:10:35
Comments (0)
Introduction to ADSL
Posted: 24/09/2007 18:59:33
Comments (0)
Wireless Security WEP WPA WPA-PSK
Posted: 24/09/2007 18:57:27
Comments (1)