Good layman's level article explaining the current state of the art on advanced dictionary based attacks using easily available equipment. The scary part is how they describe a $12k box using 8 of the GPU's that my company designs for compute and high end graphics are used to crunch through 74 BILLION MD5 hashes every SECOND!
What this means is that all manner of advanced dictionary attacks using 100M+ entry dictionaries are now computationally feasible:
http://arstechnica.com/security/2012/08/passwords-under-assault/
The bottom line is if you thought putting two common words together, and throwing a capital and a few numbers or punctuation at the end of a word was enough to thwart brute force attacks, you need to think again.
What this means is that all manner of advanced dictionary attacks using 100M+ entry dictionaries are now computationally feasible:
http://arstechnica.com/security/2012/08/passwords-under-assault/
The bottom line is if you thought putting two common words together, and throwing a capital and a few numbers or punctuation at the end of a word was enough to thwart brute force attacks, you need to think again.
Last edited: