Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

Your Password Can Probably be Cracked Faster Than You’d Think

Your Password Can Probably be Cracked Faster Than You’d Think

Whether you’re talking about identity theft, data breaches, or any other form of cybercrime, one of the leading causes of successful cyberattacks is the use of insufficiently secure passwords. Just how easy is it for someone to bypass such a password? Let’s consider the facts.

How to Crack a Password

Cybercriminals come correct, first of all. Not only do many of them have access to some pretty sophisticated tools and resources, they go about their selfish and deceitful activities with a strategy based on the average user’s online conduct.

For the cybercriminal, bypassing a password is really a numbers game. Chances are good that, if they try some commonly used passwords, a cybercriminal will eventually hit pay dirt. For instance, a cybercriminal’s first guesses could look like the following:

  • 123456789
  • guest
  • qwerty
  • password
  • a1b2c3

Since these are some of the world’s most common passwords—with an estimated 10 to 20% of accounts using a similar password—trying different variations of them or adding one or two symbols gives a cybercriminal a pretty good chance of getting in.

If we imagine ourselves to be cybercriminals, this knowledge helps to simplify our process immensely. If we invest in a password cracking tool, which effectively just tries every dictionary word and randomized combination of characters, increasing in length as it goes, chances are good that we will ultimately get in.

It’s just like trying to guess a combination lock number. While it’s going to take some time, you could try every possible combination—1-1-1, 1-1-2, 1-1-3—until you either get it, or the bike’s owner is back and not-so-politely asking you to step away from their property. 

The more variables there are to try, the more possible options there are—increasing at exponential rates, making it impossible to manually try every single combination. A computer, on the other hand, could try…and much, much faster. That’s how a password-cracking tool operates.

How Long Before a Password is Cracked?

It all depends on the password. Many of the tools that these cybercriminals will use will try the usual suspects first, and will therefore crack the password immediately. The shorter, weaker passwords can take fractions of a second, with these tools testing millions of potential credentials in that time.

It also depends on the hardware the cybercriminal is using, as a more powerful system will allow the attacker to test potential passwords that much faster. Let’s go over how speedily a reasonably powerful laptop could crack a password, based on how long the password is, and how complicated it is:

As pictured, weak—or short and simple passwords—would fold immediately, holding out for a few seconds or minutes at best. However, once a password is designed to be longer and more complex, the likelihood of a password being cracked within someone’s lifetime becomes far smaller…arguably impossible.

That is, however, assuming that your password’s length and complexity aren’t wholly reliant on a combination of otherwise common (and therefore, insecure) words or phrases. Sure, “!password12345” may seem to meet some of the basic requirements for a password—and based on the password chart above, should take a million years to figure out—the use of common password trends makes it far easier to figure out.

This is precisely why we always advocate for more stringent password practices to ensure each and every one is sufficiently secure. These practices include the aforementioned length and complexity requirements, and avoiding things that could be guessed somewhat easily, including pet names, birthdays, and other common factors. Of course, passwords should never be used more than once, as in, you need a separate password for each account you’re securing.

It is also important to keep in mind that the results generated above could be accomplished using resources that are out there and available, using a basic tool on a common laptop. An invested cybercriminal very well could have additional resources at their disposal, things like botnets and significant cloud resources, along with the hardware needed to power through a brute force attempt much faster than our hypothetical mid-range laptop could.

The big takeaway: ALWAYS use strong and secure passwords.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Wednesday, 28 January 2026

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Cloud Hackers Efficiency Hardware Network Security User Tips Internet Malware IT Support Privacy IT Services Email Workplace Tips Google Computer Phishing Collaboration Hosted Solutions Workplace Strategy Users Ransomware Mobile Device Backup Small Business Microsoft Productivity Quick Tips Managed Service Passwords Saving Money Communication Cybersecurity Smartphone Data Backup Android AI Data Recovery Upgrade Disaster Recovery Business Management Smartphones VoIP communications Mobile Devices Windows Browser Social Media Microsoft Office Managed IT Services Network Current Events Tech Term Remote Internet of Things Facebook Artificial Intelligence Information Holiday Miscellaneous Automation Covid-19 Cloud Computing Gadgets Training Server Compliance Managed Service Provider Remote Work Outsourced IT IT Support Employee/Employer Relationship Spam Encryption Windows 10 Office Data Management Government Business Continuity Wi-Fi Windows 10 Blockchain Virtualization Bandwidth Business Technology Mobile Office Two-factor Authentication Data Security Vendor Apps Networking Mobile Device Management Gmail Chrome BYOD WiFi Budget Managed Services Voice over Internet Protocol Employer-Employee Relationship Apple Tip of the week App Avoiding Downtime Computing Marketing Information Technology How To BDR Office 365 HIPAA Applications Access Control Hacker Conferencing Operating System Website Managed IT Services Risk Management 2FA Analytics Office Tips Augmented Reality Router Big Data Storage Virtual Private Network Password Healthcare Bring Your Own Device Health Help Desk Computers Retail Telephone Cybercrime Scam Solutions Data loss Cooperation Firewall Patch Management Windows 11 Save Money Remote Monitoring Vulnerability End of Support Vendor Management The Internet of Things Excel Physical Security Social Remote Workers Display Printer Paperless Office Infrastructure Monitoring Customer Service Free Resource Project Management Document Management Windows 7 Going Green Microsoft 365 Content Filtering Maintenance Antivirus Downloads YouTube Licensing Cryptocurrency Employees Word Entertainment Integration Virtual Desktop Data storage LiFi Telephone System Holidays Robot Cost Management Outlook Safety Data Storage Supply Chain Video Conferencing Money Managed Services Provider Humor IT Management VPN Virtual Machines Meetings Professional Services User Tip Modem Sports Processor Mouse Computer Repair Mobile Security iPhone Customer Relationship Management Administration Vulnerabilities Smart Technology Data Privacy Machine Learning Hacking Images 101 Saving Time Presentation Multi-Factor Authentication Mobility Settings Wireless Printing Managed IT Service Wireless Technology Twitter Alerts IP Address Hosted Solution Remote Working Download Memory Vendors Data Breach Error Google Play Be Proactive Typing Videos Browsers Electronic Health Records Connectivity Workforce Social Engineering Break Fix Remote Computing Recovery Knowledge Upload Wasting Time Threats Google Drive Social Network Trend Micro Security Cameras Workplace Strategies Multi-Factor Security Hard Drives 5G Software as a Service Tablet IoT Meta Dark Web Domains Google Docs Alert Unified Communications Experience Trends Managing Costs Amazon Managed IT Customer Resource management eCommerce File Sharing Regulations SSID Bitcoin Dark Data Google Calendar Refrigeration Running Cable Data Analysis Surveillance Star Wars Virtual Assistant Outsource IT Google Wallet How To Microsoft Excel Public Speaking Notifications Staff Lithium-ion battery Media Gamification Virtual Machine Environment Travel Social Networking Medical IT Windows 8 Legislation Laptop Entrepreneur Reviews Techology Fileless Malware Development Google Maps Transportation Small Businesses Drones Wearable Technology Content Hypervisor Displays Shopping Health IT Optimization Unified Threat Management Motherboard PowerPoint Comparison Undo Halloween Unified Threat Management Directions Assessment Employer/Employee Relationships Outsourcing Permissions Navigation PCI DSS Gig Economy Workplace Hacks Network Congestion Specifications Scary Stories Fun User Error Microchip Internet Service Provider Internet Exlporer Teamwork Hiring/Firing Fraud Evernote Paperless Deep Learning Application Regulations Compliance Username Memes Point of Sale Co-managed IT Black Friday IBM Education Net Neutrality Database SQL Server Technology Care History Tech Support IT Technicians Business Communications Financial Data Network Management Smartwatch Proxy Server IT Cookies Scams Mobile Computing Monitors Cyber Monday Search Procurement Tactics Azure Hybrid Work Hotspot Cyber security Websites Mirgation Tech Human Resources Best Practice Telework CES Communitications Nanotechnology Cables Competition Buisness Electronic Medical Records Language IT solutions SharePoint Supply Chain Management Addiction Legal Management Chatbots Term Google Apps Business Growth FinTech Lenovo IT Assessment Screen Reader IT Maintenance Writing Distributed Denial of Service Virtual Reality Computing Infrastructure User Cortana Flexibility Service Level Agreement Value Business Intelligence Server Management Private Cloud Identity Shortcuts Alt Codes Organization Digital Security Cameras Superfish Bookmark Smart Devices Identity Theft Smart Tech Ransmoware Downtime

Blog Archive