{"id":8632,"date":"2022-10-18T12:14:28","date_gmt":"2022-10-18T12:14:28","guid":{"rendered":"https:\/\/blog.bwgamespot.com\/index.php\/2022\/10\/18\/8-rtx-4090s-could-crack-most-of-your-passwords-in-just-48-minutes\/"},"modified":"2022-10-18T12:14:28","modified_gmt":"2022-10-18T12:14:28","slug":"8-rtx-4090s-could-crack-most-of-your-passwords-in-just-48-minutes","status":"publish","type":"post","link":"https:\/\/blog.bwgamespot.com\/index.php\/2022\/10\/18\/8-rtx-4090s-could-crack-most-of-your-passwords-in-just-48-minutes\/","title":{"rendered":"8 RTX 4090s could crack most of your passwords in just 48 minutes"},"content":{"rendered":"<p>Cryptomining&#8217;s off the cards, but it turns out the new <a href=\"https:\/\/www.pcgamer.com\/nvidia-geforce-rtx-4090-founders-edition-review-performance-benchmarks\/\" target=\"_blank\" rel=\"noopener\">Nvidia RTX 4090<\/a> is a dab hand at hacking and not just gaming. Stick eight of them in a password cracking rig\u2014for a paltry $13K\u2014and you can break an eight-character password in just 48 minutes. \u00a0<\/p>\n<p>The Ada Lovelace-based card keeps popping up with new metrics to prove just what an absolute beast of a GPU it&#8217;s got at its heart, and its showing in the HashCat benchmark highlights the cryptography chops of the AD102 core.<\/p>\n<p>The performance was highlighted by security researcher, <a href=\"https:\/\/twitter.com\/Chick3nman512\/status\/1580712040179826688?\" target=\"_blank\" rel=\"noopener\">Sam Croley<\/a>, who tweeted on Friday (via <a href=\"https:\/\/www.tomshardware.com\/news\/eight-rtx-4090s-can-break-passwords-in-under-an-hour\" target=\"_blank\" rel=\"noopener\">Tom&#8217;s Hardware<\/a>) that there&#8217;s &#8220;an insane &gt;2x uplift over the 3090 for nearly every algorithm.&#8221; In the same thread he also pointed out that it&#8217;s just over three times faster than AMD&#8217;s Radeon RX 6900 XT.<\/p>\n<p>Crunching the numbers, other Twitter users have suggested that would mean a modest collection of RTX 4090 cards could go through every single possible password combination of a standard eight-character password\u2014including upper- and lower-case letters, numbers, and symbols\u2014in less than an hour.<\/p>\n<p>That&#8217;s with the AD102 tested against Microsoft&#8217;s New Technology LAN Manager (NTLM) authentication protocol, which is something you&#8217;ll see in place in a whole lot of enterprise situations out there.<\/p>\n<p>That&#8217;s massively cutting the cost of password decryption, which should have you right now looking at just how secure your pet-name passwords are looking right now. Though to be fair, in 2022, the <a href=\"https:\/\/www.rd.com\/article\/passwords-hackers-guess-first\/\" target=\"_blank\" rel=\"noopener\">most common two passwords<\/a> are still 123456 and 123456789. So, for the vast majority of passwords you&#8217;re not going to need an expensive cracking rig to get through someone&#8217;s simple security.<\/p>\n<div class=\"see-more see-more--clipped\">\n<p>Mother of Eris&#8230;With these benchmarks, using an 8 GPU rig, you could go through:every.single.possible.password.combination.of an 8 character password(even total random upper, lower, number, symbol) using NTLM hashing (Windows \/ Active Directory)in&#8230;48 minutes!!! https:\/\/t.co\/nM85Lqddcl<a href=\"https:\/\/twitter.com\/TinkerSec\/status\/1580722789245280257\">October 14, 2022<\/a><\/p>\n<div class=\"see-more__filter\"><\/div>\n<div class=\"see-more__button-container\"><span class=\"see-more__button\">See more<\/span><\/div>\n<\/div>\n<p>But if a single card was to be put up against a list of the top couple of hundred passwords in use right now it may just take a few seconds, maybe milliseconds, to crack most passwords. Though chances are you&#8217;re probably not going to want what&#8217;s &#8216;hidden&#8217; behind such lax security measures.<\/p>\n<div class=\"fancy-box\">\n<div class=\"fancy_box-title\">Your next machine<\/div>\n<div class=\"fancy_box_body\">\n<div class=\"image-full-width-wrapper\">\n<div class=\"image-widthsetter\">\n<p class=\"vanilla-image-block\">\n<\/p><\/div>\n<\/div>\n<p><span class=\"credit\">(Image credit: Future)<\/span><\/p>\n<p><a href=\"https:\/\/www.pcgamer.com\/best-gaming-pc\/\" target=\"_blank\" rel=\"noopener\"><strong>Best gaming PC<\/strong><\/a>: The top pre-built machines from the pros<br \/>\n<a href=\"https:\/\/www.pcgamer.com\/best-gaming-laptop\/\" target=\"_blank\" rel=\"noopener\"><strong>Best gaming laptop<\/strong><\/a>: Perfect notebooks for mobile gaming<\/p>\n<\/div>\n<\/div>\n<p>The <a href=\"https:\/\/www.itpro.co.uk\/hardware\/components\/369322\/nvidias-rtx-4090-is-a-powerful-password-cracking-tool\" target=\"_blank\" rel=\"noopener\">original report by ITPro<\/a> should put your mind at ease, however, if you were at all concerned about rogue RTX 4090s ray tracing the hell out of Cyberpunk in the day and then cracking all your passwords by night.\u00a0<\/p>\n<p>&#8220;This kind of device is typically used for offline password cracking because online solutions would typically be resistant to such attack vectors,&#8221; Grant Wyatt, COO at MIRACL tells ITPro.<\/p>\n<p>If you are worried, though, it does point out that if you&#8217;re using a good password manager, which stores passwords between 12 and 128 characters in length, then even this sort of brute force method would take a lot longer to get through.\u00a0<\/p>\n<p>Maybe months, maybe years, maybe centuries, or even longer.<\/p>","protected":false},"excerpt":{"rendered":"<p>[#item_image]8 RTX 4090s could crack most of your passwords in just 48 minutes<!-- wp:html --><\/p>\n<p>Cryptomining&#8217;s off the cards, but it turns out the new <a href=\"https:\/\/www.pcgamer.com\/nvidia-geforce-rtx-4090-founders-edition-review-performance-benchmarks\/\" target=\"_blank\" rel=\"noopener\">Nvidia RTX 4090<\/a> is a dab hand at hacking and not just gaming. Stick eight of them in a password cracking rig\u2014for a paltry $13K\u2014and you can break an eight-character password in just 48 minutes. \u00a0<\/p>\n<p>The Ada Lovelace-based card keeps popping up with new metrics to prove just what an absolute beast of a GPU it&#8217;s got at its heart, and its showing in the HashCat benchmark highlights the cryptography chops of the AD102 core.<\/p>\n<p>The performance was highlighted by security researcher, <a href=\"https:\/\/twitter.com\/Chick3nman512\/status\/1580712040179826688?\" target=\"_blank\" rel=\"noopener\">Sam Croley<\/a>, who tweeted on Friday (via <a href=\"https:\/\/www.tomshardware.com\/news\/eight-rtx-4090s-can-break-passwords-in-under-an-hour\" target=\"_blank\" rel=\"noopener\">Tom&#8217;s Hardware<\/a>) that there&#8217;s &#8220;an insane &gt;2x uplift over the 3090 for nearly every algorithm.&#8221; In the same thread he also pointed out that it&#8217;s just over three times faster than AMD&#8217;s Radeon RX 6900 XT.<\/p>\n<p>Crunching the numbers, other Twitter users have suggested that would mean a modest collection of RTX 4090 cards could go through every single possible password combination of a standard eight-character password\u2014including upper- and lower-case letters, numbers, and symbols\u2014in less than an hour.<\/p>\n<p>That&#8217;s with the AD102 tested against Microsoft&#8217;s New Technology LAN Manager (NTLM) authentication protocol, which is something you&#8217;ll see in place in a whole lot of enterprise situations out there.<\/p>\n<p>That&#8217;s massively cutting the cost of password decryption, which should have you right now looking at just how secure your pet-name passwords are looking right now. Though to be fair, in 2022, the <a href=\"https:\/\/www.rd.com\/article\/passwords-hackers-guess-first\/\" target=\"_blank\" rel=\"noopener\">most common two passwords<\/a> are still 123456 and 123456789. So, for the vast majority of passwords you&#8217;re not going to need an expensive cracking rig to get through someone&#8217;s simple security.<\/p>\n<div class=\"see-more see-more--clipped\">\n<p>Mother of Eris&#8230;With these benchmarks, using an 8 GPU rig, you could go through:every.single.possible.password.combination.of an 8 character password(even total random upper, lower, number, symbol) using NTLM hashing (Windows \/ Active Directory)in&#8230;48 minutes!!! https:\/\/t.co\/nM85Lqddcl<a href=\"https:\/\/twitter.com\/TinkerSec\/status\/1580722789245280257\">October 14, 2022<\/a><\/p>\n<div class=\"see-more__filter\"><\/div>\n<div class=\"see-more__button-container\"><span class=\"see-more__button\">See more<\/span><\/div>\n<\/div>\n<p>But if a single card was to be put up against a list of the top couple of hundred passwords in use right now it may just take a few seconds, maybe milliseconds, to crack most passwords. Though chances are you&#8217;re probably not going to want what&#8217;s &#8216;hidden&#8217; behind such lax security measures.<\/p>\n<div class=\"fancy-box\">\n<div class=\"fancy_box-title\">Your next machine<\/div>\n<div class=\"fancy_box_body\">\n<div class=\"image-full-width-wrapper\">\n<div class=\"image-widthsetter\">\n<p class=\"vanilla-image-block\">\n<\/div>\n<\/div>\n<p><span class=\"credit\">(Image credit: Future)<\/span><\/p>\n<p><a href=\"https:\/\/www.pcgamer.com\/best-gaming-pc\/\" target=\"_blank\" rel=\"noopener\"><strong>Best gaming PC<\/strong><\/a>: The top pre-built machines from the pros<br \/>\n<a href=\"https:\/\/www.pcgamer.com\/best-gaming-laptop\/\" target=\"_blank\" rel=\"noopener\"><strong>Best gaming laptop<\/strong><\/a>: Perfect notebooks for mobile gaming<\/p>\n<\/div>\n<\/div>\n<p>The <a href=\"https:\/\/www.itpro.co.uk\/hardware\/components\/369322\/nvidias-rtx-4090-is-a-powerful-password-cracking-tool\" target=\"_blank\" rel=\"noopener\">original report by ITPro<\/a> should put your mind at ease, however, if you were at all concerned about rogue RTX 4090s ray tracing the hell out of Cyberpunk in the day and then cracking all your passwords by night.\u00a0<\/p>\n<p>&#8220;This kind of device is typically used for offline password cracking because online solutions would typically be resistant to such attack vectors,&#8221; Grant Wyatt, COO at MIRACL tells ITPro.<\/p>\n<p>If you are worried, though, it does point out that if you&#8217;re using a good password manager, which stores passwords between 12 and 128 characters in length, then even this sort of brute force method would take a lot longer to get through.\u00a0<\/p>\n<p>Maybe months, maybe years, maybe centuries, or even longer.<\/p>\n<p><!-- \/wp:html --><\/p>\n","protected":false},"author":0,"featured_media":8633,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[20],"tags":[],"_links":{"self":[{"href":"https:\/\/blog.bwgamespot.com\/index.php\/wp-json\/wp\/v2\/posts\/8632"}],"collection":[{"href":"https:\/\/blog.bwgamespot.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.bwgamespot.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.bwgamespot.com\/index.php\/wp-json\/wp\/v2\/comments?post=8632"}],"version-history":[{"count":0,"href":"https:\/\/blog.bwgamespot.com\/index.php\/wp-json\/wp\/v2\/posts\/8632\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.bwgamespot.com\/index.php\/wp-json\/wp\/v2\/media\/8633"}],"wp:attachment":[{"href":"https:\/\/blog.bwgamespot.com\/index.php\/wp-json\/wp\/v2\/media?parent=8632"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.bwgamespot.com\/index.php\/wp-json\/wp\/v2\/categories?post=8632"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.bwgamespot.com\/index.php\/wp-json\/wp\/v2\/tags?post=8632"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}