Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Gromit
Aug 15, 2000

I am an oppressed White Male, Asian women wont serve me! Save me Campbell Newman!!!!!!!

Delivery McGee posted:

On the other hand, if the government wants to log in to your banking website or SA account, it's fairly trivial to brute-force a 16-character password, given a big enough Beowulf cluster or supercomputer, especially since most people choose passwords that are easy to remember and thus easy to break. They don't have to break the encryption, they just have to break the password, and the list of passwords that hash to a certain value is relatively small, hence rainbow tables -- of course, their passwords are ideally also encrypted and may use a physical USB dongle with a rolling code ...

It is NOT fairly trivial to brute force a 16-character password (I assume we aren't talking about single DES or ROT-13 here!), and easy to remember does not necessarily equate to easy to break.

Adbot
ADBOT LOVES YOU

Gromit
Aug 15, 2000

I am an oppressed White Male, Asian women wont serve me! Save me Campbell Newman!!!!!!!

Delivery McGee posted:

It's trivial compared to a one-time pad, for the average person's stupid fuckin' password. Front-load the dictionary attack with the targets' kids' names and birthdates.

Or, for the XKCD strip you were probably inspired by, plain ol' dictionary attack. There's only so many combinations of words that fit in a certain character limit. Either way, the NSA probably has enough CPU power, far-enough-away IP addresses, and time to crack a 16-character password before the statute of limitations is out, depending on how well the server is locked down.

If by "trivial" you mean only 5 times the age of the universe instead of 1000 times, then I guess you're right. Have you even looked at AES keyspaces?

And if you really care about my inspiration, it's using the distributed password attack system I have in my lab. I use biographic dictionaries all the time and if you think people really encrypt their data with their kids names then you are sorely mistaken, at least in my law enforcement role. Maybe your run-of-the-mill computer janitor job sees a different usage pattern?

  • Locked thread