On mySimon: Issey Miyake Automatic Watch for Men
BNET Business Network:
BNET
TechRepublic
ZDNet

May 30th, 2008

Either choose strong passwords, or don't bother with a password at all

Posted by Adrian Kingsley-Hughes @ 11:40 am

Categories: How to ...

Tags: Password, Strong Password, Adrian Kingsley-Hughes

Earlier today I downloaded the latest Live CD for Ophcrack, the Windows password cracker, and tried it out on a Vista install to see how good of a password buster it is.

Conclusion: Either choose strong passwords, or don’t bother with a password at all.

Here’s the test - I took a virtual PC that uses Windows Vista that I’ve been sharing with a few friends (Fred, Barney, Betty and Wilma … you might know them) and put this up against the Live CD to see how many passwords I could recover.

The process went something like this:

  • Download Ophcrack Live CD
  • Burn a CD (although I didn’t need to do this - I just booted the virtual machine off the .ISO file)
  • Let Ophcrack do its stuff

Gallery here

 

 

 

The results were quite staggering. In less than 50 seconds three weak passwords had been recovered (shame on you pcdoc, Fred and Betty … I’m not letting you on my systems again). However, two much longer and more complex passwords (one consisting of alphanumeric characters, the other more complex) survived.

You have been warned …

Adrian Kingsley-HughesAdrian is a technology journalist and author who has devoted over a decade to helping users get the most from technology. He also runs a popular blog called The PC Doctor. See his full profile and disclosure of his industry affiliations

Want to get in touch? Got a tip? Feel free to drop me a note! I ALWAYS respect anonymity. I'm also on Twitter (@the_pc_doc)

Right to Reply: Should any industry representatives wish to comment on any posts on Hardware 2.0, I will be happy to publish their reply verbatim on this blog.

Subscribe to Hardware 2.0 via Email alerts or RSS.

  • Talkback
  • Most Recent of 23 Talkback(s)
RE: Either choose strong passwords, or don't bother with a password at all
Once you forgot the password you have to find some recovery tool.as I bought http://www.resetwindowspassword.com/
last time. but it work.... (Read the rest)
Posted by: tannpopo Posted on: 07/21/09 You are currently: a Guest | | Terms of Use
Strong login ids too!  D. T. Schmitz | 05/30/08
RE: Either choose strong passwords  garybs | 05/30/08
Download it and find out...(NT)  JCitizen | 05/31/08
Downloading now  soonerproud | 05/30/08
A useful tool  itpro_z | 05/30/08
GRC has a great password generator  marks055@... | 05/30/08
Good grief, folks, it doesn't matter!  dave.leigh@... | 05/30/08
The nth degree  D. T. Schmitz | 05/31/08
Another use for OphCrack  Lizzie_B | 05/31/08
Weak passwords are certainly bad, but they do protect you well in some case  georgeou | 06/01/08
It's pretty easy to set up an offline attack  CobraA1 | 06/01/08
Multiple factor authentication  CobraA1 | 06/01/08
Right...  dave.leigh@... | 06/01/08
Now I'm scared  Hrothgar - PCLinuxOS User | 06/01/08
Master Joe Says...  MasterJoe | 06/02/08
RE: Either choose strong passwords, or don't bother with a password at all  rhane@... | 06/02/08
Not all that  mike@... | 06/02/08
RE: Either choose strong passwords, or don't bother with a password at all  Ceridan | 06/03/08
That's why...  Cornhead | 06/04/08
RE: Either choose strong passwords, or don't bother with a password at all  flippytheclown | 06/09/08
To Avoid LM Hash, I Always Use Passwords Greater Than 15 Characters  chessmen | 06/16/08
RE: Either choose strong passwords, or don't bother with a password at all  Louise V | 06/18/08
RE: Either choose strong passwords, or don't bother with a password at all  tannpopo | 07/21/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

advertisement

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and