Security researchers show off the RTX 4090’s password cracking power

Why it matters: Security researcher and password cracker Sam Croley posted benchmarks highlighting the RTX 4090’s password-cracking muscle. Nvidia’s newest flagship GPU shattered the RTX 3090’s previous benchmark records and doubled performance across almost every algorithm tested. The cracked passwords adhered to security best practices and included random letter cases, symbols, and numbers.

According to Croley’s tweet, the mammoth GPU was tested against Microsoft’s well-known New Technology LAN Manager (NTLM) authentication protocol as well as the Bcrypt password-hacking function. All of the tests were conducted using Hashcat v6.2.6 in benchmark mode. Hashcat is a well-known and widely used password-cracking tool used by system administrators, cybersecurity professionals, and cybercriminals to test or guess user passwords.

First @hashcat benchmarks on the new @nvidia RTX 4090! Coming in at an insane>2x uplift over the 3090 for nearly every algorithm. Easily capable of setting records: 300GH/s NTLM and 200kh/s bcrypt w/ OC! Thanks to blazer for the run. Full benchmarks here: https://t.co/Bftucib7P9 pic.twitter.com/KHV5yCUkV4

— Chick3nman ” (@Chick3nman512) October 14, 2022

Based on the benchmark findings, a fully outfitted password hashing rig with eight RTX 4090 GPUs would have the computing power to cycle through all 200 billion iterations of an eight-character password in 48 minutes. The sub-one-hour result is 2.5 times faster than the RTX 3090’s previous record. Both benchmark measurements were conducted using only commercially available GPU hardware and related software.

The Hashcat software provides several attack types designed to facilitate password recovery assistance or, depending on the user, unauthorized access to another’s accounts. These attack types include dictionary attacks, combinator attacks, mask attacks, rule-based attacks, and brute force attacks.

Many of the attacks available in Hashcat and other password-cracking tools can benefit from predictable human behaviors that often result in poor security practices. For example, an attack may first focus on well-known words, terms, or patterns in an attempt to minimize the amount of time required to crack the user’s password. Using these types of lists and data in the attack can bring the time required to crack a password down from 48 minutes to mere milliseconds.

While the benchmark results may sound ominous, it’s important to note that the approach may only have a limited set of real-world use cases. MIRACL Chief Operating Officer Grant Wyatt told ITPro.com that these types of attacks are typically relegated to offline assets due to online security tools, practices, and configurations.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
5 Small Car Engines With Impressive Horsepower Output thumbnail

5 Small Car Engines With Impressive Horsepower Output

Streetmetal/Shutterstock When you talk about high output engines, you usually think about cars with lots of cylinders, like V8, V10, V12, or even W16 engines. These powerful engines include the likes of the Bugatti W-16 engine, or these V8 Dodge crate engines. However, advancements in engine design and technology means that you no longer must
Read More
How can you be fooled by the U+202E trick? (2013) thumbnail

How can you be fooled by the U+202E trick? (2013)

A common technique, used by malicious attackers to fool their victims, is using the Unicode special character U+202E known as an annulment from right to left to make the malicious file appears as a PDF document instead of a potentially dangerous executable file. To understand this concept, let's imagine that our malicious file is "document.exe"…
Read More
第2世代の「Echo Buds」が日本でも発売! ノイキャン付きで今なら1万1480円 thumbnail

第2世代の「Echo Buds」が日本でも発売! ノイキャン付きで今なら1万1480円

相変わらずコスパが強いです。Amazonが、ワイヤレスイヤホン「Echo Buds」の第2世代モデルを発表しました。昨年4月頃に海外向けに発表されていたイヤホンで、待望の日本上陸になりますね。2022年2月24日から発売予定で、定価1万2980円なんですが、現在予約注文で1万480円となっています。期限は2月23日まで。カラバリは白と黒があります。普通過ぎる、けれどそれでもよい性能すでにレビューが出ていますが、音質もノイキャンもフィット感も、それに価格も無問題といったバランス。Alexaアプリでイコライザーや操作設定のカスタムなどが可能で、プライバシー的に気になる人はAlexaのマイクをミュートにすることも。Alexaなしでも問題なく使えますが、ウェイクワードの反応はかなり早いみたい。Image: Amazonバッテリーはイヤホン単体で約5時間、ケース充電込みで最大15時間、15分の急速充電で2時間再生が可能。4サイズのイヤーチップと2種類のウィングチップが付属し、フィッティングテストもあります。この価格のイヤホンでこれほどフィット感が手厚いのは嬉しいサポートですね。Image: AmazonAmazonのページにはもう100点の比較表があるんですけど、現役の第一線ワイヤレスイヤホンたちに対して、新Echo Budsは価格がとにかく強い。弱点はバッテリーですかねぇ。充電を煩わしく感じる可能性はありそうですが、そんなときはちょい値段アップしたワイヤレス充電対応ケースを選ぶ選択肢も。こちらは定価1万4980円ですが、予約注文で3,500円オフの大盤振る舞い。こちらも2月23日まで。フィット感とコスパを重視したい人には、よい選択肢になる予感です、新Echo Buds。ヘビーに使い倒すならワイヤレス充電環境があった方がいいかもしれませんね。耳にAmazonのニヤリ顔を付けたい人にもおすすめ?※価格など表示内容は執筆時点のものです。変更の可能性もありますので、販売ページをご確認ください。Source: Amazon(1、2)
Read More
How sustainable are the 10-minute delivery services? thumbnail

How sustainable are the 10-minute delivery services?

Lebensmittel auf E-Bikes binnen Minuten nach Hause geliefert. Ein umweltfreundlicher Traum vieler Großstädter? Nicht ganz: Beim Umweltschutz gibt es noch einiges zu tun. Der deutsche Lieferdienst Gorillas verspricht, Lebensmittel in nur zehn Minuten zu liefern. picture alliance / Winfried Rothermel | Winfried Rothermel Ein paar Klicks auf dem Smartphone. Zehn Minuten warten. Und dann klingelt…
Read More
California appeals decision regarding Activision Blizzard settlement thumbnail

California appeals decision regarding Activision Blizzard settlement

Activision Blizzard’s legal troubles just took another potential turn. The California Department of Fair Employment and Housing (DFEH) is appealing a judge’s decision that denies it from intervening in the $18 million settlement between the game developer and the US Equal Employment Opportunity Commission (EEOC), according to a document filed Friday. Activision Blizzard and the…
Read More
Index Of News
Total
0
Share