The Truth About Password Length

The Cyber Mentor · Beginner ·🔐 Cybersecurity ·4y ago

Key Takeaways

The video discusses the importance of password length in cybersecurity, providing realistic insights into its impact on security, featuring The Cyber Mentor, Heath Adams.

Full Transcript

does length matter or is it more about the necessity of your complexity well when we're talking about passwords the answer to both questions is yes possibly so i want to talk today about passwords and password complexity and how we're doing passwords potentially wrong or the thoughts of passwords and doing them wrong and this is going back to a little bit of things that i already knew but now i've got some recent data to prove it from an engagement where we had 7 200 or so passwords that we we dumped out or hashes that we dumped out i should say and took those password hashes and tried cracking them and we were pretty successful within a week we were able to crack 70 of those passwords using basic rule sets basic password lists and just uh general ideas general ideas about how people work in complexity standards so i'm going to go ahead and dive into that we'll talk through it and we'll see what this looks like in a little bit more detail so moving over to microsoft excel which is high production quality but honestly the easiest way to show you this so here on column a we have hashes now these are all ntlm hashes here on column b we have the cracked password and then the length of the password here on column c now this attack against these passwords was run using a 30 90 graphics card it is considered one of the top of line graphics cards but it is a single graphics card you have cracking rigs out there that will have multiple graphics cards and they can chain them together and they can do some insane password cracking so with this i ran this attack against the initial 7 200 passwords and that attack ran for five hours now in those five hours we cracked all of these passwords here in this list so the longest one that we cracked here was a 19 character password actually we have two 19 character passwords and then they just kind of go down the list 18 17 16. and this is concerning because when we think about passwords when we think about i don't know anything that we go online and they say hey you need to have a long password and you should have a long password with a capital letter lowercase letter a number and a special character okay we'll look at this one right here we have a capital letter we have lowercase letters we have a number and we have a special character 19 characters cracked okay does not matter great length on this great policy meets the policy still got cracked okay so well we fall into a mindset here we fall into a mindset of using dictionary words which i consider to be the kryptonite of a good password we fall into the mindset often of hey i'm going to have a capital letter at the front i'm going to have a number at the end and then i'm going to have a special character at the very very end so here's where we're seeing that we're not seeing it here but we're seeing it a lot okay seeing it here and in this password policy of this company obviously looked like they did not require special characters which led to more cracking as well with this in mind we have the issue of these passwords getting cracked mainly because of the dictionary words that they are using you can see most of these are common dictionary words so with this we cracked all these passwords it's like 4 500 in this list i want to show you the passwords that attempts that we made to crack afterwards talk about the reasoning we did this and why this becomes important when it gets into complexity and we'll close out and it all makes sense so keep this in mind 19 characters moving over i then ran an attack which is a brute force attack this first attack was called a rainbow table attack basically we're taking this password we're using a word list i can add in what's called rule sets to this to kind of modify or mutate certain things within that word list to make different attempts we're going through those we're trying billions and billions and billions of possibilities and we're going through and we're trying to see um if we can actually come through here actually i think this password list when i ran it with the rule set was like a trillion possibilities or something crazy like that so we're doing a lot of hash attempts at one time so when we come through here we're using this we're trying to basically put this back into a hash format and match it with this hash if it matches we know this password is correct and then we've cracked that password here we're doing what's called a brute force attack so this changes things up a little bit we are taking eight characters minimum and we're going through and literally just brute forcing every single character this could be a capital letter lowercase letter special character number doesn't matter every single position is going to try every single possibility within an eight character range this here took almost two days now this took almost two days on a 30-90 if somebody had a really good cracking rig they could probably get this down a lot shorter now i've actually heard out of berkeley i believe somewhere has a super computer that can now crack 14 character brute forces really really fast so keep that in mind no password is really safe but we'll talk about ideas and strategies here so with this list running it across two days with my my rig we have 130 cracks pretty good these were all passwords that did not crack in the initial initial set here so the five hour attempt the first sweep didn't crack including eight character passwords why why did these passwords not crack look at them they're different most of these are kind of jumbled they're not really they still have look they still have some issues they still cap the letter at the beginning they still have numbers and then uh looks like special character at the end we're still humans we still make these mistakes but they are a lot more complex they're more jumbled up they don't make sense they're like initials and looks like different sort of things in here except for final number four um and maybe bob in here and some of these other ones but for the most part they're kind of jumbled up these are okay passwords they didn't crack initially literally had to go brute force them on a dictionary attack against these these would not crack and that is something to point out these are these are better passwords in my opinion than these passwords here and these are 8 character versus 19. now we move into nine now at nine password at the length of nine for me to crack this with my rig it would have took 242 days to go through all potential possibilities i wasn't gonna do that so what i did was i ran a few guessing attacks and we'll start down here because this is actually where i started having some progress take a capital letter we know people people is what's in mind capital letter maybe a couple lower case letters afterwards and then add a special character at the end in between can be whatever character possibility we want because who knows and then you start getting some jumbled passwords again but you still have numbers a special character at the end and we still go on to crack another 40 passwords in i don't know in seven hours on this one so this was one of those attacks where hey again i'm cracking these passwords only because they're they're taking the concept of thinking like a human and being able to crack these so as we start progressively getting longer yes passwords become harder to crack that is uh mathematical there the issue again comes back to dictionary words so we start saying okay well then what is a good password if we have to have a password now this is getting into the concept where people will start yelling at me about well it's about the hash it's about the salt um you know there are there are no password options now or or enable multi-factor yeah i get all of that okay but we're not there as a society yet a lot of places still require passwords so if we have passwords what can we do what can we do to protect ourselves here well first things first if you're going to have a password the longer the better is true if you're going to also make it complex keep that in mind the longer the better is true if you're also going to make it complex now we can generate a quick 14 character password by doing some random just like i don't know if this is 14 characters or not but just random something like this here i don't know what the length that is but with this in mind this is a decent password probably not cracking this ever uh you can run this through a word list can run this through anything not cracking it what sucks about this password well how are you going to remember this this is probably pretty difficult to remember okay the the more complex it gets the the more our human brains go oh my gosh i'm stumped here so you have other options you can do dictionary words you can say like i like long walks on the beach at around 5 00 p.m and then you could still add your exclamations whatever at the end in this password here not getting cracked i like long walks on the beach at around 5 p.m okay add some capital letters in there throw it around nobody's cracking this password just plain and simple so you can still have your dictionary words if as a human you want to think like that the other alternative is what i consider misspellings intentional misspelling so something like if you had pepperoni pizza 2021 that's a password that i would likely crack but if you start doing like pepperoni uh something like this pepperoni and then pizza this is still gonna be harder to crack than the other one you start adding in like i don't know something like this pepperoni pizza this is gonna be way harder to crack okay um as you get into the lead speak now i still don't recommend this but it's still better than it's still better than this okay um at a significantly less length here or it might be similar actually but this is a stronger password than the longest cracked password there so with that in mind my big recommendation is using something like a password manager now password manager such as bit warden now i have no affiliation with bit warden this is not a paid promotion this is me saying i like bit warden and why do i like bit warden mainly because of this part right here where it says hey we're open source what does that mean that means they're transparent you can go read their source code and they will provide it to you you can go look for bugs in it and that means by community we can all look for bugs in this platform and i feel a lot safer when something is open source now you can go through the platform what it does is if you've never used a password manager this will store your passwords you can use it to generate you can see a little generator right here generate passwords it's a nice feature go in there and generate some passwords um add complexity and it'll store all your passwords me personally i don't know majority of the passwords i know my password for my um my bit warden and that's about it okay now this does bring into the point of single point of failure which is true we have to pick our battles do we want the same password being used every single place and that almost becomes a single point of failure as well if you have the same password being used on your amazon on your facebook and your github like they're showing here or do you want three different passwords there but somebody ever gets your point of failure for your bit warden then or you get your password for your bit word and then yeah you've lost all those which then brings me to the other concept which many you if you're security-minded are probably screaming in your head enable two-factor authentication enable multi-factor authentication have something out there that prevents you if your account gets attacked have something out there that prevents you from just letting them log right in now this could be an authenticator app like the google authenticator app it could be something like sms which as security-minded folks we don't like to recommend but sms based multi-factor or two-factor is still better than no multi-factor or two-factor so keep in mind strong passwords length does matter but complexity doesn't matter combination of the two is even better get away from the dictionary words would help you out tremendously from me hacking your passwords doesn't matter if your meeting policy doesn't matter if you have a 19 character password if it has dictionary if it has no complexity then we are looking at some problems for you from a hacker perspective good day for me now with that in mind using something like multi-factor authentication two-factor authentication great concept password managers great concept this will prevent a lot of the issues out there that we are seeing and stop uh somebody like me in my tracks or even better somebody that's actually out there to get you maliciously in their tracks so that is it for this video hopefully you understood you enjoyed the concepts i highly recommend checking out password managers highly recommend enabling 2fa mfa and keeping yourself safe online as technology gets better as hackers improve as it becomes easier and easier to crack a password you need to keep yourself safe so that's it for this video if you liked it please hit the like button please do consider subscribing half of you that watch these videos still aren't subscribed we'd love to have you here as a subscriber hit the bell and then comment down below if you have any ideas for a video you would like to see in the future until then my name is the cyber mentor and i do thank you for joining me peace out

Original Description

Does it actually matter how long your passwords are? Heath Adams takes a look in this video and provides some realistic insight into the difference they make. Drop your thoughts in the comments and remember to subscribe if you found this video interesting! #passwordsecurity #cybersecurity #securityawareness ❓Info❓ ___________________________________________ Hire me: https://tcm-sec.com Learn to hack: https://academy.tcm-sec.com Get certified: https://certifications.tcm-sec.com 🔹The Cyber Mentor Merch🔹 ___________________________________________ https://teespring.com/stores/the-cyber-mentor 📱Social Media📱 ___________________________________________ Website: https://thecybermentor.com Twitter: https://twitter.com/thecybermentor Twitch: https://www.twitch.tv/thecybermentor Discord: https://discord.gg/tcm LinkedIn: https://www.linkedin.com/in/heathadams 💸Donate💸 ___________________________________________ Like the channel? Please consider supporting me on Patreon: https://www.patreon.com/thecybermentor Support the stream (one-time): https://streamlabs.com/thecybermentor Hacker Books: Penetration Testing: A Hands-On Introduction to Hacking: https://amzn.to/31GN7iX The Hacker Playbook 3: https://amzn.to/34XkIY2 Hacking: The Art of Exploitation: https://amzn.to/2VchDyL The Web Application Hacker's Handbook: https://amzn.to/30Fj21S Real-World Bug Hunting: A Field Guide to Web Hacking: https://amzn.to/2V9srOe Social Engineering: The Science of Human Hacking: https://amzn.to/31HAmVx Linux Basics for Hackers: https://amzn.to/34WvcXP Python Crash Course, 2nd Edition: https://amzn.to/30gINu0 Violent Python: https://amzn.to/2QoGoJn Black Hat Python: https://amzn.to/2V9GpQk My Build: lg 32gk850g-b 32" Gaming Monitor:https://amzn.to/30C0qzV darkFlash Phantom Black ATX Mid-Tower Case: https://amzn.to/30d1UW1 EVGA 2080TI: https://amzn.to/30d2lj7 MSI Z390 MotherBoard: https://amzn.to/30eu5TL Intel 9700K: https://amzn.to/2M7hM2p G.SKILL 32GB DDR4 RAM: https://amzn.to/2M6
Watch on YouTube ↗ (saves to browser)
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from The Cyber Mentor · The Cyber Mentor · 0 of 60

← Previous Next →
1 Buffer Overflows Made Easy - Part 1: Introduction
Buffer Overflows Made Easy - Part 1: Introduction
The Cyber Mentor
2 Buffer Overflows Made Easy - Part 2: Spiking
Buffer Overflows Made Easy - Part 2: Spiking
The Cyber Mentor
3 Buffer Overflows Made Easy - Part 3: Fuzzing
Buffer Overflows Made Easy - Part 3: Fuzzing
The Cyber Mentor
4 Buffer Overflows Made Easy - Part 4: Finding the Offset
Buffer Overflows Made Easy - Part 4: Finding the Offset
The Cyber Mentor
5 Buffer Overflows Made Easy - Part 5: Overwriting the EIP
Buffer Overflows Made Easy - Part 5: Overwriting the EIP
The Cyber Mentor
6 Buffer Overflows Made Easy - Part 6: Finding Bad Characters
Buffer Overflows Made Easy - Part 6: Finding Bad Characters
The Cyber Mentor
7 Buffer Overflows Made Easy - Part 7: Finding the Right Module
Buffer Overflows Made Easy - Part 7: Finding the Right Module
The Cyber Mentor
8 Buffer Overflows Made Easy - Part 8: Generating Shellcode and Gaining Shells
Buffer Overflows Made Easy - Part 8: Generating Shellcode and Gaining Shells
The Cyber Mentor
9 HackTheBox - Sunday Walkthrough (Re-Up)
HackTheBox - Sunday Walkthrough (Re-Up)
The Cyber Mentor
10 Networking for Ethical Hackers - TCP, UDP, and the Three-Way Handshake (Re-Up)
Networking for Ethical Hackers - TCP, UDP, and the Three-Way Handshake (Re-Up)
The Cyber Mentor
11 Networking for Ethical Hackers - Network Subnetting (Re-Up)
Networking for Ethical Hackers - Network Subnetting (Re-Up)
The Cyber Mentor
12 Networking for Ethical Hackers - Network Subnetting Part 2: The Challenge (Re-Up)
Networking for Ethical Hackers - Network Subnetting Part 2: The Challenge (Re-Up)
The Cyber Mentor
13 Networking for Ethical Hackers - Building A Basic Network with Cisco Packet Tracer (Re-Up)
Networking for Ethical Hackers - Building A Basic Network with Cisco Packet Tracer (Re-Up)
The Cyber Mentor
14 HackTheBox - Fighter Walkthrough (Re-Up)
HackTheBox - Fighter Walkthrough (Re-Up)
The Cyber Mentor
15 Beginner Linux for Ethical Hackers - Navigating the File System
Beginner Linux for Ethical Hackers - Navigating the File System
The Cyber Mentor
16 Beginner Linux for Ethical Hackers - Users and Privileges
Beginner Linux for Ethical Hackers - Users and Privileges
The Cyber Mentor
17 Beginner Linux for Ethical Hackers - Common Network Commands
Beginner Linux for Ethical Hackers - Common Network Commands
The Cyber Mentor
18 Beginner Linux for Ethical Hackers - Viewing, Creating, and Editing Files
Beginner Linux for Ethical Hackers - Viewing, Creating, and Editing Files
The Cyber Mentor
19 Beginner Linux for Ethical Hackers - Controlling Kali Services
Beginner Linux for Ethical Hackers - Controlling Kali Services
The Cyber Mentor
20 Beginner Linux for Ethical Hackers - Scripting with Bash
Beginner Linux for Ethical Hackers - Scripting with Bash
The Cyber Mentor
21 Beginner Linux for Ethical Hackers - Installing and Updating Tools
Beginner Linux for Ethical Hackers - Installing and Updating Tools
The Cyber Mentor
22 Cracking Linux Password Hashes with Hashcat
Cracking Linux Password Hashes with Hashcat
The Cyber Mentor
23 Reminder: Twitch Hacking Live Stream Tonight! 2/26/19 at 8PM EST
Reminder: Twitch Hacking Live Stream Tonight! 2/26/19 at 8PM EST
The Cyber Mentor
24 Hacking Live Stream: Episode 1 - Kioptrix Level 1, HackTheBox Jerry, and Career Q&A / AMA
Hacking Live Stream: Episode 1 - Kioptrix Level 1, HackTheBox Jerry, and Career Q&A / AMA
The Cyber Mentor
25 Hacking Live Stream: Episode 2 - HackTheBox Active, Vulnserver Buffer Overflow, and Career Q&A / AMA
Hacking Live Stream: Episode 2 - HackTheBox Active, Vulnserver Buffer Overflow, and Career Q&A / AMA
The Cyber Mentor
26 Hacking Live Stream: Episode 3 - Hack The Box Blue, Devel, and Career Q&A / AMA
Hacking Live Stream: Episode 3 - Hack The Box Blue, Devel, and Career Q&A / AMA
The Cyber Mentor
27 New Zero to Hero Pentest Course, New Website, and 2K Subs?!
New Zero to Hero Pentest Course, New Website, and 2K Subs?!
The Cyber Mentor
28 Zero to Hero Pentesting: Episode 1 - Course Introduction, Notekeeping, Introductory Linux, and AMA
Zero to Hero Pentesting: Episode 1 - Course Introduction, Notekeeping, Introductory Linux, and AMA
The Cyber Mentor
29 Zero to Hero Pentesting: Episode 2 - Python 101
Zero to Hero Pentesting: Episode 2 - Python 101
The Cyber Mentor
30 Zero to Hero Pentesting: Episode 3 - Python 102, Building a Terrible Port Scanner, and a Giveaway
Zero to Hero Pentesting: Episode 3 - Python 102, Building a Terrible Port Scanner, and a Giveaway
The Cyber Mentor
31 Zero to Hero Pentesting: Episode 4 - Five Phases of Hacking + Passive OSINT
Zero to Hero Pentesting: Episode 4 - Five Phases of Hacking + Passive OSINT
The Cyber Mentor
32 Zero to Hero Pentesting: Episode 5 - Scanning Tools (Nmap, Nessus, BurpSuite, etc.) & Tactics
Zero to Hero Pentesting: Episode 5 - Scanning Tools (Nmap, Nessus, BurpSuite, etc.) & Tactics
The Cyber Mentor
33 Zero to Hero Pentesting: Episode 6 - Enumeration (Kioptrix & Hack The Box)
Zero to Hero Pentesting: Episode 6 - Enumeration (Kioptrix & Hack The Box)
The Cyber Mentor
34 Zero to Hero Pentesting: Episode 7 - Exploitation, Shells, and Some Credential Stuffing
Zero to Hero Pentesting: Episode 7 - Exploitation, Shells, and Some Credential Stuffing
The Cyber Mentor
35 Installing Windows Server 2016 on VMWare in 5 Minutes
Installing Windows Server 2016 on VMWare in 5 Minutes
The Cyber Mentor
36 Zero to Hero: Week 8 - Building an AD Lab, LLMNR Poisoning, and NTLMv2 Cracking with Hashcat
Zero to Hero: Week 8 - Building an AD Lab, LLMNR Poisoning, and NTLMv2 Cracking with Hashcat
The Cyber Mentor
37 A Day in the Life of an Ethical Hacker / Penetration Tester
A Day in the Life of an Ethical Hacker / Penetration Tester
The Cyber Mentor
38 Active Directory Exploitation - LLMNR/NBT-NS Poisoning
Active Directory Exploitation - LLMNR/NBT-NS Poisoning
The Cyber Mentor
39 Zero to Hero: Week 9 - NTLM Relay, Token Impersonation, Pass the Hash, PsExec, and more
Zero to Hero: Week 9 - NTLM Relay, Token Impersonation, Pass the Hash, PsExec, and more
The Cyber Mentor
40 Zero to Hero: Episode 10 - MS17-010/EternalBlue, GPP/cPasswords, and Kerberoasting
Zero to Hero: Episode 10 - MS17-010/EternalBlue, GPP/cPasswords, and Kerberoasting
The Cyber Mentor
41 Writing a Pentest Report
Writing a Pentest Report
The Cyber Mentor
42 Zero to Hero: Week 11 - File Transfers, Pivoting, and Reporting Writing
Zero to Hero: Week 11 - File Transfers, Pivoting, and Reporting Writing
The Cyber Mentor
43 The Complete Linux for Ethical Hackers Course for 2019
The Complete Linux for Ethical Hackers Course for 2019
The Cyber Mentor
44 Full Ethical Hacking Course - Beginner Network Penetration Testing (2019)
Full Ethical Hacking Course - Beginner Network Penetration Testing (2019)
The Cyber Mentor
45 Popping a Shell with SMB Relay and Empire
Popping a Shell with SMB Relay and Empire
The Cyber Mentor
46 Pentesting for n00bs: Episode 1 - Legacy (hackthebox)
Pentesting for n00bs: Episode 1 - Legacy (hackthebox)
The Cyber Mentor
47 Pentesting for n00bs: Episode 2 - Lame
Pentesting for n00bs: Episode 2 - Lame
The Cyber Mentor
48 Pentesting for n00bs: Episode 3 - Blue
Pentesting for n00bs: Episode 3 - Blue
The Cyber Mentor
49 Web App Testing: Episode 1 - Enumeration
Web App Testing: Episode 1 - Enumeration
The Cyber Mentor
50 Pentesting for n00bs: Episode 4 - Devel
Pentesting for n00bs: Episode 4 - Devel
The Cyber Mentor
51 Pentesting for n00bs: Episode 5 - Jerry
Pentesting for n00bs: Episode 5 - Jerry
The Cyber Mentor
52 Web App Testing: Episode 2 - Enumeration, XSS, and UI Bypassing
Web App Testing: Episode 2 - Enumeration, XSS, and UI Bypassing
The Cyber Mentor
53 Pentesting for n00bs: Episode 6 - Nibbles
Pentesting for n00bs: Episode 6 - Nibbles
The Cyber Mentor
54 Web App Testing: Episode 3 - XSS, SQL Injection, and Broken Access Control
Web App Testing: Episode 3 - XSS, SQL Injection, and Broken Access Control
The Cyber Mentor
55 How NOT to Approach a Cybersecurity Mentor
How NOT to Approach a Cybersecurity Mentor
The Cyber Mentor
56 Web App Testing: Episode 4 - XXE, Input Validation, Broken Access Control, and More XSS
Web App Testing: Episode 4 - XXE, Input Validation, Broken Access Control, and More XSS
The Cyber Mentor
57 Pentesting for n00bs: Episode 7 - Optimum (hackthebox)
Pentesting for n00bs: Episode 7 - Optimum (hackthebox)
The Cyber Mentor
58 Pentesting for n00bs: Episode 8 - Bashed (hackthebox)
Pentesting for n00bs: Episode 8 - Bashed (hackthebox)
The Cyber Mentor
59 Pentesting for n00bs: Episode 9 - Grandpa
Pentesting for n00bs: Episode 9 - Grandpa
The Cyber Mentor
60 Top 5 Internal Pentesting Methods
Top 5 Internal Pentesting Methods
The Cyber Mentor

The video explores the significance of password length in cybersecurity, offering practical advice on password security, and is suitable for beginners interested in cybersecurity and password management.

Key Takeaways
  1. Assess current password security
  2. Understand password length recommendations
  3. Implement strong password policies
  4. Use password managers for secure storage
  5. Regularly update and strengthen passwords
💡 Password length is a critical factor in determining the security of a password, but it's not the only consideration, and a balanced approach to password security is essential.

Related Reads

📰
Virus MAYUNDO à l’UNIKIN : Quand mon propre PC s’est fait piéger (et comment sauver vos fichiers)
Learn how to protect your files from viruses spread through USB drives and recover your data if infected
Medium · Cybersecurity
📰
The Frontline of Modern Cyber Defense
Learn how cyberattacks often start with harmless-looking events like phishing emails or malicious URLs and why a multi-step approach is crucial for modern cyber defense
Medium · Cybersecurity
📰
Why Proactive Threat Hunting Matters in Managed Cybersecurity
Proactive threat hunting is crucial in managed cybersecurity to detect and respond to threats before they cause harm, rather than just reacting to alerts
Medium · Cybersecurity
📰
I Tracked Myself Using AI — What I Found Kept Me Up All Night
A person used AI to track themselves and found sensitive information in 40 minutes, highlighting cybersecurity concerns
Medium · Cybersecurity
Up next
NordVPN Coupon Code 2026 | Exclusive Discount + 4 FREE Months
Tutorial Stack
Watch →