Vulnerabilities / Threats
8/16/2010
01:37 PM
Connect Directly
RSS
E-Mail
50%
50%

Passwords Quickly Hacked With PC Graphics Cards

Georgia Tech researchers find that high-end, readily available graphics processing units are powerful enough to easily crack secret codes.




Slideshow: Cloud Security Pros And Cons
(click for larger image and for full photo gallery)
Passwords with fewer than 12 characters can be quickly brute-force decoded using a PC graphics processing unit (GPU) that costs just a few hundred dollars, according to researchers at the Georgia Institute of Technology.

"We've been using a commonly available graphics processor to test the integrity of typical passwords of the kind in use here at Georgia Tech and many other places," said Richard Boyd, a senior research scientist at the university's research institute, in a statement. "Right now we can confidently say that a seven-character password is hopelessly inadequate."

Today's top graphics processors offer about two teraflops of parallel processing power. For comparison, "in the year 2000, the world's fastest supercomputer, a cluster of linked machines costing $110 million, operated at slightly more than 7 teraflops," he said.

The barrier to using multi-core graphics processors -- available from Nvidia or AMD's ATI division -- for compute-intensive processes other than graphics processing, said Boyd, first fell in 2007, when Nvidia released a C-based software development kit. "Once Nvidia did that, interest in GPUs really started taking off," he said. "If you can write a C program, you can program a GPU now." Or use it to crack a password.

Furthermore, thanks to Moore's Law, graphics processors continue to increase in power, which means that GPUs will get better, not worse, at cracking passwords.

But who needs a graphics processor? People often create and rely on simple passwords, and many websites use passwords more for psychological than security purposes.

But the Georgia Tech research underscores the importance of getting people to adopt longer, non-simple passwords to make them safer against attack. "Length is a major factor in protecting against 'brute forcing' a password," according to one research scientist involved in the project, Joshua Davis. "A computer keyboard contains 95 characters, and every time you add another character, your protection goes up exponentially, by 95 times."

For the record, to defend against GPU attacks, the password researchers recommend using sentence-length passwords that mix letters with numbers or symbols, and which are at least 12 characters long.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ANON1241631011972
50%
50%
ANON1241631011972,
User Rank: Apprentice
11/1/2011 | 6:35:42 PM
re: Passwords Quickly Hacked With PC Graphics Cards
I think this article overstates the capabilities and the use case does not generally exist in the real world. Passwords do not exist in a cyberspace vacuum, just waiting to be attacked in isolation. They exist in combination with a user identifier and a challenge/response system behind a UI. While the brute force methods may be capable of generating all the possible combinations, they still have to test them against a validation challenge with the correct response set. Most password challenge systems have two additional inhibitors against brute force attacks: 1. They don't respond at GPU speeds 2. They usually disable the account after 3 to 5 failed attempts. So, unless the brute force program has the password database available and the appropriate decode algorithms to provide the correct challenge/response patterns, it will not succeed. If the attacker has that kind of access, he or she is already past the firewall and well into the bowels of the network.
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5242
Published: 2014-10-21
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter in a get_template action.

CVE-2012-5243
Published: 2014-10-21
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request.

CVE-2012-5702
Published: 2014-10-21
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) company_name parameter in an addedit action to i...

CVE-2013-7406
Published: 2014-10-21
SQL injection vulnerability in the MRBS module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2014-4514
Published: 2014-10-21
Cross-site scripting (XSS) vulnerability in includes/api_tenpay/inc.tenpay_notify.php in the Alipay plugin 3.6.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to the getDebugInfo function.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.