Technology Get the latest on technology, electronics and software…

Password security - hacked

Thread Tools
 
Old Sep 26, 2014 | 04:04 PM
  #1  
cabanalane's Avatar
Thread Starter
Racer
 
Joined: Nov 2010
Posts: 329
Likes: 8
Password security - hacked

How does an account password get hacked?


Many logins now have security levels with combination of letters, number, upper case, and special character. And also won't allow common English words.


Isn't that enough? Normal person can't logically figure it out. I don't see how a computer can, even at nano second speed to run through all the possible combinations.


So shouldn't all passwords be "secured" as-is?


Or is it more a case of, for every 100 guys that choose a strong password combination, someone is going to choose ABC123 as their password.
Reply
Old Sep 26, 2014 | 04:12 PM
  #2  
imj0257's Avatar
Q('.')=O
15 Year Member
Liked
Loved
Community Favorite
iTrader: (1)
 
Joined: Feb 2008
Posts: 23,566
Likes: 730
From: DFW, TX
ask Target.
Reply
Old Sep 26, 2014 | 04:43 PM
  #3  
stogie1020's Avatar
Needs more Lemon Pledge
 
Joined: Mar 2005
Posts: 52,768
Likes: 2,000
From: Phoenix, AZ
What happens (generally) is as follows:

1. Web site stores your username and HASH of your password (proprietary algorithmic representation of your password that only the algorithm holder should be able to decipher).

2. Hacker accesses list of usernames and password HASHES, along with PW hints.

3. Hacker examines the list for the most common HASHES. Begins testing accounts with the most commonly used passwords (Jesus, Password, abc123, etc...).

4. Hacker ALSO looks at password hints amongst the most commonly occurring HASHES for hints that are actually the user's password (some people do this). If 1000 users all have the same HASH, and one of those users left "Jesus" as their PW hint, there is a good chance that user, and the other 999 used the password "Jesus".

Lather, rinse, repeat.
Reply
Old Sep 26, 2014 | 04:45 PM
  #4  
stogie1020's Avatar
Needs more Lemon Pledge
 
Joined: Mar 2005
Posts: 52,768
Likes: 2,000
From: Phoenix, AZ
I encourage everyone to use Two Factor Authentication with any account that allows it.

With 2FA, even if someone discovers your password, they would also need your cellphone to be able to receive the text (most common method) in order to access the account. For now.
Reply
Old Sep 26, 2014 | 04:50 PM
  #5  
Whiskers's Avatar
Go Giants
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Aug 2004
Posts: 70,003
Likes: 1,260
From: PA
Ask Stogie
Reply
Old Sep 26, 2014 | 04:52 PM
  #6  
stogie1020's Avatar
Needs more Lemon Pledge
 
Joined: Mar 2005
Posts: 52,768
Likes: 2,000
From: Phoenix, AZ
Reply
Old Sep 26, 2014 | 05:03 PM
  #7  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey
Hacker gets your email address from facebook. Pretty good chance that is your username. Hacker goes to amazon, home depot, etc. and hits the "i forgot password" link. System asks hacker "what was your high school mascot?" Hacker hits your facebook page to see where you went to high school. You just been haxored.
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
eastcoastguy
3G TL (2004-2008)
25
Oct 29, 2015 03:00 PM
SUPRMN84
3G TL Audio, Bluetooth, Electronics & Navigation
5
Oct 7, 2015 09:46 PM
MilanoRedDashR
3G TL (2004-2008)
5
Sep 27, 2015 10:15 PM
Matthew Purpura
1G CL (1997-1999)
3
Sep 25, 2015 06:10 PM
James Alexander
3G TL Audio, Bluetooth, Electronics & Navigation
1
Sep 15, 2015 07:48 AM




All times are GMT -5. The time now is 10:06 AM.