Do You Use Password Haystacking?

September 27, 2016 | Views: 10463

Begin Learning Cyber Security for FREE Now!

FREE REGISTRATIONAlready a Member Login Here

How can we make passwords memorable AND uncrackable, it is password haystacking. You know the phrase it’s like trying to find a needle in a haystack; well the same method applies by hiding your password with a prefix and suffix pattern.  We know length is the most important element in supporting an uncrackable password, well at least in our life time.  It is a process of using some phrase that has meaning to you and hiding it with a creative pattern.

Example password creation:  I Played College BasketBall My Number Was 34. IPCBBMNw34

 

Example pattern creation:  Used the number 3 and 4 on the keyboard to start the prefix and suffix pattern, that I would remember easily, #$#$//IPCBBMNw34\#$#$ this gives me a memorable and uncrackable password.

Time Required to Exhaustively Search this Password’s Space:

Online Attack Scenario:

(Assuming one thousand guesses per second)

9.88 hundred million trillion trillion centuries

Offline Fast Attack Scenario: 

(Assuming one hundred billion guesses per second)

9.88 trillion trillion centuries

Massive Cracking Array Scenario: 

(Assuming one hundred trillion guesses per second)

9.88 billion trillion centuries

For more information please see https://www.grc.com/haystack.htm

Share with Friends
FacebookTwitterLinkedInEmail
Use Cybytes and
Tip the Author!
Join
Share with Friends
FacebookTwitterLinkedInEmail
Ready to share your knowledge and expertise?
26 Comments
  1. Very informative article on password haystacking.
    Thank you for the tutorial.

  2. I do something similar but have it customized for each login site, an example is using a haystack password as a base password and from the website, using a phrase or keyword that I know of the site, I add the two together and form a larger PW, sort of a hash.

  3. I hadn’t really thought of that. Nice.

Page 3 of 5«12345»
Comment on This

You must be logged in to post a comment.

Our Revolution

We believe Cyber Security training should be free, for everyone, FOREVER. Everyone, everywhere, deserves the OPPORTUNITY to learn, begin and grow a career in this fascinating field. Therefore, Cybrary is a free community where people, companies and training come together to give everyone the ability to collaborate in an open source way that is revolutionizing the cyber security educational experience.

Support Cybrary

Donate Here to Get This Month's Donor Badge

 
Skip to toolbar

We recommend always using caution when following any link

Are you sure you want to continue?

Continue
Cancel