Password Cracking - Computerphile

Поділитися
Вставка
  • Опубліковано 12 лип 2016
  • 'Beast' cracks billions of passwords a second, Dr Mike Pound demonstrates why you should probably change your passwords...
    Please note,at one point during the video Mike suggests using SHA512. Please check whatever the recommended process is at the time you view the video.
    Here's a look at 'Beast': • BEAST & The GPU Cluste...
    How NOT to Store Passwords: • How NOT to Store Passw...
    Password Choice: • How to Choose a Passwo...
    Deep Learning: • Deep Learning - Comput...
    Cookie Stealing: • Cookie Stealing - Comp...
    / computerphile
    / computer_phile
    This video was filmed and edited by Sean Riley.
    Computer Science at the University of Nottingham: bit.ly/nottscomputer
    Computerphile is a sister project to Brady Haran's Numberphile. More at www.bradyharan.com

КОМЕНТАРІ • 4,7 тис.

  • @kahnfatman
    @kahnfatman 2 роки тому +185

    Q: What are you using the graphics card for?
    A: Well -- terminal apps.

    • @n0tjak
      @n0tjak 4 місяці тому +1

      alacritty users using an opengl-accelerated terminal so the cpu works less

  • @Big_Tex
    @Big_Tex 5 років тому +4590

    My password is unbreakable because I'm using my name followed by the digits of pi. All of them.

    • @justinreyesv
      @justinreyesv 4 роки тому +390

      an unending password? youre gonna crash the db~ space limit

    • @Tipko
      @Tipko 4 роки тому +74

      clever boy

    • @Mars-1995
      @Mars-1995 4 роки тому +152

      Well not hashable. Nice try

    • @hawsh3066
      @hawsh3066 4 роки тому +39

      Big brain time

    • @castles990
      @castles990 4 роки тому +19

      big brain

  • @OmarMohammed-fy2he
    @OmarMohammed-fy2he 3 роки тому +693

    ""iloveyoukate" 14:46 he's risking his accounts for you kate. I hope you guys didn't split up 😂

    • @alpha_wolf_80
      @alpha_wolf_80 3 роки тому +5

      I was going to comment the same thing

    • @ishansheikh3058
      @ishansheikh3058 3 роки тому +7

      that guy was not keeping password for sure. he was feeling emotional while doing whatever he was doing. Emotions = Hacked.

    • @ryanmcgowan3061
      @ryanmcgowan3061 3 роки тому +16

      Kate doesn't even know he exists.

    • @tolep
      @tolep 3 роки тому +13

      It is Kate herself, advised by some shrink.

    • @Luiz997488
      @Luiz997488 2 роки тому +8

      The "iloveyoukate" virgin vs the Chad "freakpower1"

  • @cheddarfish225
    @cheddarfish225 Рік тому +101

    It would be interesting to revisit this topic and see how things have changed in the past 6 years.

    • @chemicallystimulated476
      @chemicallystimulated476 Рік тому +2

      Can you suggest me any such videos

    • @mully006
      @mully006 Рік тому +19

      For one thing the 4x Titan X GPU he has are are roughly equivalent to an RTX 4070 which is a ~$700 GPU. The modern equivalent of his system (say 4x 4090) is around 50 time faster than his system.

    • @kaspervestergaard2383
      @kaspervestergaard2383 6 місяців тому

      Wait really? @@mully006

  • @MaxMakerChannel
    @MaxMakerChannel 8 років тому +1713

    Love this guy. He should be teaching.

    • @Computerphile
      @Computerphile  8 років тому +571

      +Max Musterman he does, at The University of Nottingham ☺️

    • @ghostlink2027
      @ghostlink2027 8 років тому +283

      That's it, I'm transferring.

    • @zinkzxd2891
      @zinkzxd2891 8 років тому +16

      Agreed.

    • @zzyzxyz5419
      @zzyzxyz5419 8 років тому +14

      Paused the video just so I would say the same thing!

    • @gammelhund
      @gammelhund 7 років тому +5

      Not to mention right here :)

  • @QuizzingHobbit
    @QuizzingHobbit 4 роки тому +1696

    Password dictionary:
    1. password
    2. user
    3. correcthorsebatterystaple

  • @anonymus3219
    @anonymus3219 2 роки тому +22

    I love how the videos have this 'unscripted' feel and they feel like they're real conversations

  • @mark..
    @mark.. Рік тому +26

    Back in the day, this video (along with your "how to choose a password" video) taught me a huge amount. I think an update could be very valuable for many people. It seems that Lastpass recently lost password vaults for millions of people, which I think will create a lot of interest in this subject.

  • @crispynugget3616
    @crispynugget3616 7 років тому +5237

    that awkward moment when you see your password...

  • @RacingAtHome
    @RacingAtHome 5 років тому +2152

    "We don't store passwords unencrypted in a database because that's a terrible, terrible idea."
    You would be surprised.

  • @nbrugman1980
    @nbrugman1980 3 роки тому +380

    Mike: "So if your password is 6 characters long, its being cracked right now, and its being cracked quickly"
    Me:

    • @rogerio067072
      @rogerio067072 2 роки тому

      🤣🤣🤣

    • @TheSystemaSystem
      @TheSystemaSystem 2 роки тому

      What's your password?

    • @maybona
      @maybona 2 роки тому +2

      thanks just bought some pizza pans from amazon

    • @Anklejbiter
      @Anklejbiter 2 роки тому +7

      My password with 6 characters: *sweating profusely*
      My password with 31 characters: *hah, mere mortals.*

    • @Johnof1000Suns
      @Johnof1000Suns 2 роки тому +3

      My password is 7 characters long, so take that hackers.

  • @gothsiN
    @gothsiN 4 роки тому +214

    Pausing at 16:38
    ma man had a freaking HEX Code as a PW and still got cracked.
    ahahhahahha damn this guy is so funny and smart. mad respect to u mike.

    • @potatofuryy
      @potatofuryy 2 роки тому +1

      RIP, that’s rough

    • @gchcom6902
      @gchcom6902 2 роки тому +26

      That's not a hex code he set as a password. That's just the program not being able to display the special characters. If you convert the hex code to to ASCII, the password is "kindé"

    • @gothsiN
      @gothsiN 2 роки тому +4

      @@gchcom6902 oohh thanks for that.

    • @bassmaiasa1312
      @bassmaiasa1312 Рік тому

      That doesn't seem like it would be very hard to crack. The character set is just 16 characters. If the person thought he was being clever, there's could be 10 million people who had the same idea and the cracking software has seen it all before. It's probably not much harder to crack than 12345678.
      I just assume I'm never going to come up with some clever password trick that at least 1 million human beings haven't already thought of.

    • @buslir2000
      @buslir2000 Рік тому +1

      @@gchcom6902 My guess would be kindé (using utf-8)

  • @_ten
    @_ten 5 років тому +1746

    computer took about 1 second to look through about 40,000,000,000 hashes
    10:13 human took about 1 second to multiply 26 times 2

    • @uniqueusername_
      @uniqueusername_ 4 роки тому +137

      Well, that's not a very fair comparison, is it? Computers are, at their core, all made for mathematical functions. Humans, on the other hand, are not. When it comes to "close enough," humans are generally better.

    • @emmiexss
      @emmiexss 4 роки тому +206

      @@uniqueusername_ Oh really? I thought i could run through a 40bil database that is stored in my head. *Heavy sarcasme.*

    • @sallybugs1695
      @sallybugs1695 4 роки тому +40

      Remember it was built by human

    • @rasmusekdahl2772
      @rasmusekdahl2772 4 роки тому +27

      uniqueusername_1024 R/FUCKINGWOOOOOOOOSH

    • @matte_luna
      @matte_luna 4 роки тому +12

      @@uniqueusername_ r/whoooosh

  • @ATSGemwolf
    @ATSGemwolf 8 років тому +4943

    I'm surprised that Tobey Maguire knows this much about hacking...

    • @jonm5195
      @jonm5195 5 років тому +102

      I thought he was Elija Wood

    • @Svendzeen
      @Svendzeen 5 років тому +131

      Well you see... After he lost the role as Spiderman, he had to get a new job. So he became Hackerman :)

    • @sirdeakia
      @sirdeakia 5 років тому +180

      He did stay a long time on the web though

    • @forgottenvy
      @forgottenvy 5 років тому +29

      sirdeakia
      Underrated comment. Why didn't people get this? It's gold.

    • @DavidVercettiMovies
      @DavidVercettiMovies 5 років тому +9

      I know for sure in that bag with the english flag there's his Spiderman outfit!

  • @BicheTordue
    @BicheTordue 4 роки тому +689

    my password is L1pZ7z3qy so it's pretty secure, nobody gonna find out

    • @esquilax5563
      @esquilax5563 4 роки тому +115

      All I see when you enter that is a string of asterisks

    • @shadowterrarian4073
      @shadowterrarian4073 4 роки тому +17

      Thanks for the revelation.

    • @cactus806
      @cactus806 4 роки тому +22

      👌no one will ever now this passwords

    • @realszn
      @realszn 4 роки тому +37

      if u enter ur credit card number it gets blocked see
      **** **** **** ****

    • @BicheTordue
      @BicheTordue 4 роки тому +15

      @@realszn here's all the number present on my card 54120

  • @guitarist1
    @guitarist1 4 роки тому +49

    this video made me change my password in all my social media accounts, and bank accounts, online games, buy a new house, move to a completely isolated planet and use encrypted network connection that runs through several illegal VPN networks. I am now living happily here in Mars. Thanks.

    • @user-jg1yn9lm2g
      @user-jg1yn9lm2g 2 роки тому +1

      Nice

    • @names_are_useless
      @names_are_useless 2 роки тому +1

      I know this is a joke comment, but using an illegal, an "untrusted", VPN is a TERRIBLE idea. You could be feeding your Computer Information to Cyber Criminals by connecting to an Untrusted VPN.
      Something worth thinking about for those wanting to go the Cheap/Free route for VPNs.

    • @fredthomson3253
      @fredthomson3253 2 роки тому

      *Thanks_Turnercyber🙏*

  • @RealCaptainAwesome
    @RealCaptainAwesome 6 років тому +2099

    So you're saying pA55w0rd is not a good choice?

    • @virtualfroggy
      @virtualfroggy 6 років тому +291

      Michael Burke no, try password123

    • @stan2880
      @stan2880 6 років тому +185

      123456 takes the longest to crack

    • @Tradinghonest
      @Tradinghonest 6 років тому +107

      99999 or zzzzz depending on the algorythm

    • @Tekrow
      @Tekrow 6 років тому +110

      *hacker voice*
      I'm in

    • @stefankrautz9048
      @stefankrautz9048 6 років тому +12

      10^6 combinations (?)

  • @atti1120
    @atti1120 8 років тому +1712

    kate i think your boyfriends pass is hacked

    • @TheMrKeksLp
      @TheMrKeksLp 8 років тому +3

      yeah lol

    • @gunjeetsingh90
      @gunjeetsingh90 8 років тому +92

      Oh no not his boyfriend's.. His secret admirer's

    • @GaffsNotLaffs
      @GaffsNotLaffs 8 років тому

      +Attila U Random characters letter and symbols. around 30+ of them.

    • @Tim-Jaeger
      @Tim-Jaeger 8 років тому +1

      +Attila U well I was in a house were the password was something like this: 9684263675467468447836794598211636063674678
      only the length is the same but I think it is hard to crack

    • @DaBeastDoesMinecraft
      @DaBeastDoesMinecraft 7 років тому +3

      Mine is something like this
      5927592058295712395736189037483194721948271930183
      49 random digits.

  • @questionable-cf1tt
    @questionable-cf1tt 4 роки тому +291

    14:47 'ganjagoblin'
    best password ever, even if it shows up on the cracked list 😂

    • @JigawattMusic
      @JigawattMusic 3 роки тому +5

      420

    • @Gamer-uf1kl
      @Gamer-uf1kl 3 роки тому +9

      Ganja means bald in hindi, so might be the reason

    • @calanm7880
      @calanm7880 3 роки тому +1

      I cracked up when camera focused on that on screen - glad you highlighted it 😀

    • @arpitpatel5312
      @arpitpatel5312 2 роки тому +3

      @@Gamer-uf1kl it also means weed or heroin, not sure which one.

    • @Gamer-uf1kl
      @Gamer-uf1kl 2 роки тому +1

      @@arpitpatel5312 cannabis/marijuana

  • @Zero11_ss
    @Zero11_ss 5 років тому +636

    Really good video dude. No silly music or fast cuts and no annotation spam on the screen, subscribed.

    • @jamesedwards3923
      @jamesedwards3923 5 років тому +18

      I think a lot of video editing courses encourage people to do the music thing. Dude I am hear for the data above else. Not the music. It gets distracting. Even with a lot of gamer videos. I can not stand it.
      You are trying to focus on the tactics and insights. Like studying with the music blasting. Sometimes it helps, but often it is a distraction.

    • @firmware1000
      @firmware1000 4 роки тому +2

      photographer

    • @marcusholloway1147
      @marcusholloway1147 3 роки тому +3

      Bruh just create a python script that encrypts an input and since only you have this encryption system it's very safe

    • @Dtr146
      @Dtr146 3 роки тому

      That's why a lot of websites require you to have a special character and a capital letter. The most common way of doing it is capitalizing the first letter and putting the special character at the end though

    • @adriannuske
      @adriannuske 2 роки тому

      @@Dtr146 How did you know my passwords!?

  • @ImAzraa
    @ImAzraa 8 років тому +80

    Just for your information, the "Beast" machine may be fast for a regular home user, but it is incredibly underpowered compared with a server-grade solution for compute workloads.
    Imagine several racks of servers with 4 cards each. Those are available out there, and regular people can build them too with the right amount of money, or rent time on them for relatively cheap

  • @BenjaminMills
    @BenjaminMills 3 роки тому +11

    I've learned (or at least read) about a ton of this stuff, and still, I thought it was Interesting to hear you step through a password attack in addition to hearing how modern tech and modern hacking techniques approach cracking passwords. Thank you sir.

  • @nellgwyn2723
    @nellgwyn2723 3 роки тому +46

    Really amazing video and quite informative even for curious dummies like me! Honestly it's just fun to watch the guys talk about their passion and learn a little even if i don't get all the details, but it's worth the effort to understand a little more about the technology we all live with.

    • @ErikOosterwal
      @ErikOosterwal 2 роки тому +3

      You can think of "hashing" algorithms, like MD5 or SHA512, as being a secret decoder ring, like the ones you used to get in a box of Alpha Bits, only a bit more sophisticated.

  • @CBusschaert
    @CBusschaert 8 років тому +323

    Now I kind of want a video about Lastpass or Dashlane and how these password manager are secure (or not). Seems like the logical follow up.

    • @treahblade
      @treahblade 8 років тому +18

      I watched a video from DefCON about this sorta thing and actually they are a 2 edged sword. They are bad because then all the attacker has to do is get your database file or hack your password into the password manager, and good because they prevent keyloggers from getting passwords.

    • @CBusschaert
      @CBusschaert 8 років тому

      treahblade I guess so

    • @Prometheus720
      @Prometheus720 8 років тому +23

      If you use Keepass then you don't have to worry about external security. Only your own files on your own computer. And you need 1 password to be secure. That's it.

    • @callummunro7380
      @callummunro7380 8 років тому +10

      I've never used a password manager, it seems illogical to have all your passwords behind one password. And where do you store the master password without needing _another_ password?

    • @yellowdockooo5907
      @yellowdockooo5907 8 років тому

      Yep

  • @xisumavoid
    @xisumavoid 8 років тому +745

    Fantastic video! Loved it :-) Good to know i am doing my passwords right, different one for every site too!

    • @Zxios
      @Zxios 7 років тому +62

      omg its a wild xisuma comment from 8 months ago!

    • @Morten_S_Olesen
      @Morten_S_Olesen 7 років тому +53

      LOL i love scrolling through random videos comments and just finding a Xisuma comment with only 5 likes (make it 6)
      Nice to know that Xisuma watches the same videos as me xD

    • @nemplayer1776
      @nemplayer1776 6 років тому +8

      Wow, I keep seeing you on a lot of videos... lol

    • @nemplayer1776
      @nemplayer1776 6 років тому +4

      Morten lol same

    • @josephlbj
      @josephlbj 6 років тому +5

      You keep following me around everywhere I go!

  • @MaZe741
    @MaZe741 4 роки тому +52

    Kind of a disappointment that he never mentioned "salting" passwords before hashing them, which makes this attack completely useless if you dont know what salt was used

    • @Chlorate299
      @Chlorate299 2 роки тому +8

      And even if you *do* know what salt was used, computing rainbow tables *per user* would take a substantial amount of time for a large dictionary.

    • @_piulin_
      @_piulin_ 2 роки тому +2

      you mean pepper.
      salt is saved with the hash, so it just slows you down (a bit).

    • @kalebbruwer
      @kalebbruwer 2 роки тому +5

      @@_piulin_ A salt wouldn't slow you down if you're attacking a specific user, but it would make the attack difficult to generalize since every user has a different salt and the passwords you test must have the salt at the end.

    • @_piulin_
      @_piulin_ 2 роки тому +1

      @@kalebbruwer I know, that's what I meant. If you hacked a server and got the hash file, then it's way slower when it's salted to interpret all the hashes, so you can sell them.

  • @MaZe741
    @MaZe741 4 роки тому +112

    Fun fact: The odds of you picking the same password as another guy are HIGHER than picking a username that already exists.

    • @Jay-S04
      @Jay-S04 3 роки тому +10

      not if my passwords look like siUn$2$8’clwo!&/ienzla!!:&*’eisnJbdKbs&29,£~*£\’Idk&/9

    • @jangtheconqueror
      @jangtheconqueror 3 роки тому +44

      @@Jay-S04 That's been added to the dictionary now

    • @PranshuTheGamer
      @PranshuTheGamer 2 роки тому +2

      @@Jay-S04 i use keepass, do mine look like that

    • @verchiel_8295
      @verchiel_8295 2 роки тому +3

      Not a fact, but closer to a hypothesis

  • @AgglomeratiProduzioni
    @AgglomeratiProduzioni 5 років тому +233

    14:42 "I love you Kate" aww

  • @GodKingOfThePlanet
    @GodKingOfThePlanet 8 років тому +477

    ANyone else burst out laughing when they saw someone had used ganjagoblin as their pass?

    • @s.p9189
      @s.p9189 8 років тому +52

      Your icon almost got me there damn.

    • @RussellTeapot
      @RussellTeapot 8 років тому +3

      it always get me. the worse is the fly one, I don't know if you never saw that, but *DAMN* each time I try to swipe the screen like a fool

    • @Blitzcreeper239
      @Blitzcreeper239 8 років тому +3

      +Russell Teapot The spider is facing 45° left, I don't get how it can startle anyone ever since scrolling means it moves upwards diagonally. Won't judge though :/

    • @s.p9189
      @s.p9189 8 років тому +2

      Well I wasnt scrolling when I was reading the comment but yeah once I scrolled I realized it wasnt real :/

    • @nathanvanthof866
      @nathanvanthof866 8 років тому +12

      did you see "iloveyoukate" at 14:49?

  • @GreatKnightJ
    @GreatKnightJ 4 роки тому +5

    The video that made me change to a password manager. 4 years later and never looked back. Thanks Mike!

  • @ishaan600
    @ishaan600 3 роки тому +2

    Dude this is a really great explanation, I have to really thank you for this

  • @wafflejam8284
    @wafflejam8284 4 роки тому +694

    11:41 he just dodged that pop up

  • @tompov227
    @tompov227 8 років тому +19

    This guy is my fav Computerphile guy

  • @typicalhog
    @typicalhog 3 роки тому +14

    Imagine seeing your password getting cracked in this video...

  • @mikeg3660
    @mikeg3660 2 роки тому

    Scary… never thought about the hashes being stolen and put into a single file for this type of repetitive attack… defeats the thought of locking an account after a few failed attempts. Learned something again from this channel…. Thank you!

    • @thebritishindian1
      @thebritishindian1 2 роки тому

      I could also never understand how passwords were brute force hacked when most services lock you out after 3 attempts. It never occurred to me that most of these databases are hacked off-line! This was a great video.

  • @toddbod94
    @toddbod94 7 років тому +971

    when websites ask for passwords and force you to fit narrow criteria like "must be between 8 and 12 characters and must contain at least 1 number (with no repeating adjacent numbers) and must contain at least 1 capital and 1 special character" are just reducing the search space for hackers.

    • @thunderbolt997
      @thunderbolt997 6 років тому +52

      but isnt that putting in more variables for computer to check making it harder?

    • @chrisspencer6502
      @chrisspencer6502 6 років тому +35

      Not really as like he said it relies on use of common words so if your use zWq0£jL3s, there is no logical combination this would occur in words

    • @usernamesaregay222
      @usernamesaregay222 6 років тому +385

      But If I'm cracking these then I know that
      1) I can skip all passwords under 8 and over 12 characters
      2) I know that all passwords will have a number so I don't need to try any passwords that don't have them
      3) same for capitals and special characters

    • @dot.5423
      @dot.5423 6 років тому +1

      This comment was aimed at thunderbolt my bad.

    • @tapwater424
      @tapwater424 6 років тому +122

      There are more combinations of passwords with 8 letters than there are from 1-7 combined. Forcing at least 1 number also increases combinations from 26^8 to 36^8.

  • @StewartW12
    @StewartW12 6 років тому +525

    A lot of people think "I'm going to go onto some website and test how strong my password is"... Those people are having their password stored away in a database to be added to someone's password dictionary.

    • @thegambler9994
      @thegambler9994 5 років тому +35

      Either that, or some other third party injected Javascript into the page.

    • @zacharyjohnson9911
      @zacharyjohnson9911 5 років тому +14

      You can use Fiddler, Wireshark, or your browser's network inspector to see if any web requests are being sent out.

    • @Josh350
      @Josh350 5 років тому +2

      Which is why I don't use those websites for obvious reasons.

    • @decycle2912
      @decycle2912 4 роки тому +5

      there's a password in my head that I never use lol

    • @georgek4416
      @georgek4416 4 роки тому

      Yes.

  • @kevinwestrom4775
    @kevinwestrom4775 4 роки тому +4

    This video needs to be updated, to be shown at current levels of computer technology with the most modern CPUs & GPUs widely available to everyone.

  • @cuttlefishn.w.2705
    @cuttlefishn.w.2705 4 роки тому +200

    "If it's stored in plaintext, then all bets are off"
    I have all my passwords encrypted with Caesar's cypher! Beat that!

  • @Bred.wards1
    @Bred.wards1 Рік тому +2

    I watched this video when it came out years ago. Recently, my dad passed away and we couldn’t remember his iCloud password to access the photos on his phone and other stuff like that. But I remembered this video, and I went and found password cracking tools for iCloud and was able to use educates guesses and the tools to find the correct password. So thank you for making this video ❤️

  • @zyphicx9868
    @zyphicx9868 8 років тому +365

    The best hashing algorithm: Google Translate!

    • @randomcatdude
      @randomcatdude 6 років тому +83

      Make your password a wikipedia page google translated a dozen times.

    • @Anankin12
      @Anankin12 6 років тому +14

      RandomCatDude wouldn't work, they update the algorithm too often, those cheeky bastards

    • @ohad219
      @ohad219 5 років тому +2

      No man Google translate just translates

    • @danifalkjensen
      @danifalkjensen 5 років тому +3

      @@randomcatdude only 12times do it 100+times
      a dozen of something is 12 of something

    • @YouTubeWatcher9000
      @YouTubeWatcher9000 5 років тому +13

      Dani Jensen I think everyone knows what a dozen is

  • @chrism3790
    @chrism3790 7 років тому +831

    I didn't know Peter Parker was a damned hacker.

    • @usseal922
      @usseal922 5 років тому +41

      I have a theory: in this Alternate Spiderverse, Peter Parker (by Tobey Maguire) got fed up with chasing low-budget criminals in NY, quit his cr*ppy job and moved into the UK. There he developed an English accent, got a degree (and later a PhD) in cybersecurity to protect his new identity and since he already had close relations with the Web ;) So, this would be the origin story of Dr. Mike Pound

    • @StevenAzari
      @StevenAzari 5 років тому +8

      @@usseal922 Ha I only had to scroll 5 comments to get to here. This makes the op fact.

    • @BillBodkin
      @BillBodkin 5 років тому +6

      i cant unsee that now

    • @LafferStyle
      @LafferStyle 5 років тому +7

      I thought he did web design

    • @VinnieZDX
      @VinnieZDX 5 років тому

      Lol

  • @Wyld1one
    @Wyld1one Рік тому +4

    it's been six years. so what hardware is used now? like to see the diffrence

    • @2rotten4you
      @2rotten4you Місяць тому

      a year late but usually i believe some hackers will buy 4090s with ill gotten gains
      really depends on how much money the attacker has

  • @cuttlefishn.w.2705
    @cuttlefishn.w.2705 4 роки тому +6

    Anybody else come back to this video, not to learn anything, but because this guy's voice is just so soothing?

  • @firen777
    @firen777 7 років тому +115

    5:18 "MD-5 should not be used by anyone ever, EVER again."
    Meanwhile, in the Yahoo's headquarter...

    • @jamesedwards3923
      @jamesedwards3923 5 років тому +2

      Amusing.

    • @benishmael9451
      @benishmael9451 5 років тому +1

      I'm dying 😁

    • @roninryu6992
      @roninryu6992 4 роки тому

      Could you help me understand? Was he just checking to see if he could guess the LinkedIn pass words that were stolen? Im trying to understand how this would work for an actual site, because after you try the wrong password several times, you get booted, or blocked, and the user gets notified. How would this actually work? Are they taking these passwords and entering them against a live site? If that is the case wouldnt the hacker get blocked after a few seconds? Plus with 2FA, is this even relevant?

    • @nilen
      @nilen 4 роки тому +1

      Ronin Ryu are you serious? 😂😂😂

    • @tradeflow5153
      @tradeflow5153 4 роки тому

      Nils Svanstedt yes I’m serious asshole

  • @SweetJP.
    @SweetJP. 6 років тому +25

    I just love this! not only because there's no chance my password will be found, but because even the most hardcore IT dudes in my area (including 2 schools I worked at) use horrible passwords, to secure thousands of pupils' social security numbers etc. At my first job, I demanded that the passwords got changed, or I would not work there as i'd be targetted for irresponsible care, in case we got hacked. Sadly they refused to change and I quit my job.

  • @edwinadeya6197
    @edwinadeya6197 4 роки тому +26

    My password one was cracked with out any software,
    Me: let's make it harder
    Him: is it password two
    Me: how did you do that

  • @dragonbusa7827
    @dragonbusa7827 3 роки тому

    Pure pleasure by listening to this guy! Thank you

  • @GummieI
    @GummieI 5 років тому +467

    15:35 "Now luckily, these leaks happen all the time" Interesting... choice of words ;)

    • @WofWca
      @WofWca 4 роки тому +19

      He's telling how to crack passwords, what do you expect?

    • @pranavdeshpande4538
      @pranavdeshpande4538 4 роки тому +14

      Also that smirk on his face when he said dive
      That might be his hacker name

    • @tcideh4929
      @tcideh4929 3 роки тому

      Cause its getting more exposure...

  • @_aullik
    @_aullik 8 років тому +221

    you forgot to link in the description

    • @Computerphile
      @Computerphile  8 років тому +50

      Thanks, now sorted >Sean

    • @OsamaRana
      @OsamaRana 8 років тому +2

      +Computerphile what is the disadvantage of designing your own hash for your own service? Wouldnt not knowing the hash procedure effectively eliminate the ability to crack passwords by using this method? Thanks.

    • @rondowar
      @rondowar 8 років тому +5

      +Osama Rana
      also, often enough if they can get to your database, you should assume your code also isn't safe

    • @OsamaRana
      @OsamaRana 8 років тому

      Thank you everyone for the insightful comments.
      Ps, I like the phrase "security through obscurity". That was exactly what I was thinking

    • @liesdamnlies3372
      @liesdamnlies3372 8 років тому +12

      'I like the phrase "security through obscurity".'
      You got that this is a bad thing, right? Like, really bad? Just checking.

  • @shakeelforester4430
    @shakeelforester4430 2 роки тому

    Since about 2015 i've had 12 character passwords with numbers, uppercase, lowercase and symbols. So glad I did that

  • @TransSappho
    @TransSappho 3 роки тому

    This is the exact video which convinced me to use much better passwords that are immune to just about every attack

  • @jampig1884
    @jampig1884 5 років тому +145

    This is why Peter wasn't allowed around computers.

  • @MrMKFreak
    @MrMKFreak 7 років тому +203

    You probably DONT want to test your passwords strength on online services that claim to only tell you how good your password is. While most of those services are probably safe to use, you can never know what service is also making it's own little (or huge?) dictionaries with just the awesome and secure passwords you give them to "test" for you.

    • @FluorescentGreen5
      @FluorescentGreen5 6 років тому +6

      solution: disconnect from the internet before you type your password and close the tab before reconnecting

    • @fray2748
      @fray2748 6 років тому +12

      Theoretically still insecure

    • @muabyt7333
      @muabyt7333 6 років тому +19

      Ein Frosch~ howsecureismypassword.net is save. Its fully written in Javascript and you can look for the code yourself

    • @douwehuysmans5959
      @douwehuysmans5959 5 років тому +3

      Best passwords are sentences like "cow curry diagram!2n;"

    • @jamesedwards3923
      @jamesedwards3923 5 років тому +8

      What you have to realize. Is that the longer and more complicated your password is. The harder it is for a computer to compromise. Given enough time, energy, and technology. All passwords are easy. Each time an encryption standard is compromised. You migrate to something else. It is a never ending race.

  • @alfonsokenjiprayogo5613
    @alfonsokenjiprayogo5613 3 роки тому +36

    Why does the british lecturer always look like a Counter-Stirik Hostage.

    • @jessicahsmith4815
      @jessicahsmith4815 3 роки тому +2

      I recover my instagram account back through *hackerlouis05* on instagram he’s legit and reliable 🏻 🏻 🏻
      Contact @hackerlouis05 on Instagram for your hacking services he’s legit and reliable

    • @alfonsokenjiprayogo5613
      @alfonsokenjiprayogo5613 3 роки тому

      @@jessicahsmith4815 thanks, Jessica Smith, Very cool.

    • @topsunnn
      @topsunnn 3 роки тому

      Omega lul

  • @HypnoticSuggestion
    @HypnoticSuggestion 2 роки тому

    This just autoplayed for me, and I recall watching back then. Incredibly the specs on those graphics cards are somewhat pedestrian now, compared to something like a newer specialized Nvidia card; I can't imagine how much easier this has become.

  • @Locut0s
    @Locut0s 8 років тому +196

    Can you believe that the bank I use has a MAXIMUM of 6 character length on the passwords used for online banking!? I have complained to them before. But to no avail. And this is not a small bank!

    • @moute_3
      @moute_3 8 років тому +62

      You should change banks then, they are just begging to have their database leaked.

    • @jarmo_kiiski
      @jarmo_kiiski 8 років тому +17

      Yep, You'd need to compute 2.8147498*10^14 hashes assuming that the passwords use extended ascii characters and also assuming that you know the hashing algorithm used. (Which can be achieved in a few seconds)

    • @Thorpe
      @Thorpe 8 років тому +8

      +moute3 Yes but the banks have other forms of authentication, including inputting specific characters of a secret answer and generating codes using your phone or hardware key.

    • @Correctrix
      @Correctrix 8 років тому +25

      Locut0s That doesn't make sense. That would be a reason for _not mandating_ long passwords. It can't be a reason for _forbidding_ long passwords. The only explanation for the latter is idiocy.

    • @janh.
      @janh. 8 років тому +5

      Locut0s I have to agree with Correctrix that if what you said is the case, then I can see why they accept weak passwords. But it does not explain why they would prevent experienced users from setting a strong password by having a maximum of 8 characters.

  • @edwardqueen5791
    @edwardqueen5791 4 роки тому +159

    "Forgot my password"
    "You're receiving this e-mail because you've clicked on 'forgot my password' on our website. Here it is in plain text for anyone to see. Your password is: JustCheckingIfThisWebsiteStoresPasswordsProperly"

    • @surrealdynamics4077
      @surrealdynamics4077 4 роки тому +10

      That's pretty clever right there. Now I have to try doing that. Thanks

  • @dylandowdy3687
    @dylandowdy3687 4 роки тому +221

    "I've been running it about ...
    18:15 checks wrist ... "10 seconds now"
    not wearing a watch and looked completely serious
    XD XD XD

    • @gtc4189
      @gtc4189 4 роки тому +11

      XD XD XD almost as if it could potentially just be habit and he clearly realized instantly he didn't have a wrist watch on at the moment XD XD XD

    • @kelpkelp5252
      @kelpkelp5252 4 роки тому +1

      @@gtc4189 XD XD XD

    • @Sackguy
      @Sackguy 3 роки тому +2

      Plot twist: he didnt havr a wirst at all

    • @kelpkelp5252
      @kelpkelp5252 3 роки тому +1

      Wurst.

    • @jessicahsmith4815
      @jessicahsmith4815 3 роки тому

      I recover my instagram account back through *hackerlouis05* on instagram he’s legit and reliable 🏻 🏻 🏻
      Contact @hackerlouis05 on Instagram for your hacking services he’s legit and reliable

  • @Silverballer48c
    @Silverballer48c 10 місяців тому

    20:03 that subtle "End the video now pls" motion

  • @7timus
    @7timus 4 роки тому +62

    The moment when Mike reads your password loud and shows it to 2 mil other people just on second random pause... If I could only be as lucky in some other lottery. :(

  • @unixfreak
    @unixfreak 5 років тому +11

    Amazing how far computer processing has come in the past 20 years. I remember messing about with brute force hashing on an i486, and it took forever.

  • @MaterialMatt
    @MaterialMatt 3 роки тому

    i just love ur explanations

  • @prathmesh646
    @prathmesh646 4 роки тому +2

    I need this professor!❤️

  • @marcuslola
    @marcuslola 7 років тому +412

    14:48 "ganjagoblin" lmao

    • @williameriksson8767
      @williameriksson8767 5 років тому +8

      marcuslola Thats my password

    • @rock3tcatU233
      @rock3tcatU233 5 років тому +2

      420 blaze it.

    • @CryptoData
      @CryptoData 4 роки тому +1

      hahahahahahahaha

    • @Inoculum
      @Inoculum 4 роки тому +9

      I am now changing my password to "ganjagoblin"... consequences be damned!

    • @darkhorsedre
      @darkhorsedre 4 роки тому

      bro I caught that too - had to left arrow to confirm lol

  • @k1ngjulien_
    @k1ngjulien_ 8 років тому +1085

    I am wondering how many of the viewers just saw their password in the video ^^

    • @mikes333
      @mikes333 8 років тому +128

      Totally got mine. 14:46 ILOVEYOUKATE

    • @thoughtyness
      @thoughtyness 8 років тому +15

      +Mike S I used to have that one only without "you" in it.

    • @callummunro7380
      @callummunro7380 8 років тому +162

      Everyone loves Kate, that's the problem

    • @samvid1992
      @samvid1992 8 років тому +20

      18:51 ashishiscool is my friend's password and his name is ashish.

    • @x1legoman1x
      @x1legoman1x 8 років тому

      +Филип Брчић genius XDDDDD

  • @wbfaulk
    @wbfaulk 3 роки тому +7

    "Let's show you an example dictionary."
    cd: No such file or directory
    (11:55)

  • @auchucknorris
    @auchucknorris 4 роки тому +8

    instantly checks what my encryption service on the back end is using O.O.

  • @Mike-Smith
    @Mike-Smith 8 років тому +10

    I like all Computerphile (and Numberphile) videos, but just wanted to say how great this particular one is. More please from Dr Mike Pound. (And prof Brailsford of course!)

  • @mctooch
    @mctooch 7 років тому +28

    I love these videos. This guy is such a great teacher. Thank you!

  • @wickedwolf8438
    @wickedwolf8438 3 роки тому

    i love the vibe this guy has about this stuff

    • @jessicahsmith4815
      @jessicahsmith4815 3 роки тому +1

      I recover my instagram account back through *hackerlouis05* on instagram he’s legit and reliable 🏻 🏻 🏻
      Contact @hackerlouis05 on Instagram for your hacking services he’s legit and reliable

    • @wickedwolf8438
      @wickedwolf8438 3 роки тому

      @@jessicahsmith4815 imagine actually making a fake account to self promote to the people who doesn't care :D...(especially to those who can "recover instagram account" themselves ; ))

  • @basedaf5580
    @basedaf5580 3 роки тому

    Wow, very informative!!!!!!! dont know how im not subbed to this channel yet

  • @professorl4208
    @professorl4208 4 роки тому +8

    An update for those of you who are watching this now - I don't know if this wasn't the case back then, but nowadays you use a hash algorithm that is slow by design, like Bcrypt, so that attackers are limited by the speed of the algorithm rather than exclusively by the grade of their hardware.

  • @mursie100
    @mursie100 8 років тому +33

    This is actually scary, I have a LinkedIn account and I use the same password fo many other sites.
    I will change all my passwords after writing this comment, and you should do too.

    • @gblargg
      @gblargg 8 років тому +13

      Just don't change all your passwords to a single new one hah.

    • @icedragon769
      @icedragon769 8 років тому +2

      Use a password manager. It can change them all for you automatically, and all to different passwords, and all to extremely secure passwords.

    • @dkmg
      @dkmg 8 років тому +4

      Friends. Use KeePass, it's free, open source and multiplatform. Change all your passwords. Use unique password per site. Let me know if you have any questions.

    • @DavidWillanski
      @DavidWillanski 8 років тому +6

      The only password I know is the one that unlocks my Keepass database.

    • @dkmg
      @dkmg 8 років тому +1

      I have KeePass on my computer and KeePass2Android on my phone. Install Dropbox to both pc and phone. Save your database or database copy there so it can be access in your pc and mobile.

  • @yousafamin007
    @yousafamin007 3 роки тому

    Superb it really works it is the first video which is really helping

  • @alexandrulupu725
    @alexandrulupu725 4 роки тому

    Hey, just watched your video. Thumbs up ! Do you do password recovery?

  • @fdk7014
    @fdk7014 8 років тому +225

    No mention of password salting?

    • @black_platypus
      @black_platypus 8 років тому +1

      Are you talking about permutating your actual passwords, or salting the hashes before storing them in a database?

    • @IceMetalPunk
      @IceMetalPunk 8 років тому +47

      That's in the Tom Scott video about storing passwords.

    • @koori049
      @koori049 8 років тому +14

      they weren't talking about securing servers they were talking about how to crack the passwords. adding salt doesnt protect at all against the attack he used, it just makes him repeat the attack for the group of paswords with a particular salt. That would be a great followup though.

    • @KhalilEstell
      @KhalilEstell 8 років тому +9

      Or peppering.

    • @Diggnuts
      @Diggnuts 8 років тому +12

      koori049 "it just makes him repeat the attack for the group of paswords with a particular salt"
      Well, yes, if you know the salting method you could have a guess, but the most basic of static salts can make the most awful password extremely hard to brute-force, at least as long as the salt it unknown.

  • @SchubertDipDab
    @SchubertDipDab 5 років тому +5

    Really love this presentation style. More in-depth stuff please especially with exploits!

  • @Bacon420
    @Bacon420 3 роки тому

    150gb password file + hashcat using your video card GPU = any password in minutes. I use the process in the last step to getting all my neighbors wifi passwords, though the possibilities are unlimited. I can do it from anywhere with a $13 wifi card on Amazon.. I felt so gangster when it worked so well right away. Oh wow, I was typing this up before you really got into it. hahah you just explained some hashcat! Nice. To compare, the same process took 3-10 days in 1998. Now it's about 3-10 min for a great password. I was a wireless network engineer.

  • @robertocariza990
    @robertocariza990 3 роки тому

    Really good video dude

  • @onee
    @onee 7 років тому +117

    Obviously 123456 is the best password out there. And in case that doesn't work anymore. You just change it to 654321. *Genius!*

    • @bin4709
      @bin4709 5 років тому

      brilliant

    • @Zooiest
      @Zooiest 5 років тому

      No, 12345

    • @buckiez
      @buckiez 5 років тому

      @@Zooiest No, 1

    • @Zooiest
      @Zooiest 5 років тому +1

      BuckieTheCat Your password has to be 5-32 characters long.

    • @kasimshahid6786
      @kasimshahid6786 5 років тому

      Thanks what's your email? Lol

  • @bhavik.knight
    @bhavik.knight 5 років тому +581

    "We don't save password unencrypted." Facebook left the chat 😂🤣

    • @jamesedwards3923
      @jamesedwards3923 5 років тому +8

      Hence why you change your password at least once a year.

    • @anatolfigeac4645
      @anatolfigeac4645 4 роки тому +2

      Lol

    • @jamesedwards3923
      @jamesedwards3923 4 роки тому +8

      You would be surprised how long some passwords can be if the service allows it.

    • @BlackVogel1
      @BlackVogel1 4 роки тому

      Talk-Power removed

    • @anel3423
      @anel3423 4 роки тому

      They encrypts the passwd ( I guess)

  • @Jack-Lack
    @Jack-Lack 4 роки тому +3

    16:30 As it displays passwords from the rockyou database, I'm seeing a password that starts with "qwerty" quite a lot. In fact, at one point at 16:34, there was a run of 3 of them within 5 results.

  • @PeterMayeku
    @PeterMayeku 4 роки тому

    Very Insightful.

  • @budjy1
    @budjy1 7 років тому +729

    14:47 "ganjagoblin" XD

  • @-._.--._.--._.--._.--._.--._.-
    @-._.--._.--._.--._.--._.--._.- 8 років тому +171

    "Change your hashes to something like SHA512 really quickly"
    Rather recommend bcrypt or something of the like.

    • @talideon
      @talideon 8 років тому +1

      You need many, many more upvotes.

    • @fdagpigj
      @fdagpigj 8 років тому +1

      Or just use Secure Remote Password and not have to worry about your database getting leaked?

    • @fdagpigj
      @fdagpigj 8 років тому

      Cíat Ó Gáibhtheacháin I feel like I'm missing something obvious, but why do you need to store users' passwords?

    • @jurek-zz3un
      @jurek-zz3un 8 років тому

      rsa 4096

    • @talideon
      @talideon 8 років тому +8

      ***** You don't store the passwords: you store something for checking if a password is valid.

  • @tasyarahmadjuli_
    @tasyarahmadjuli_ 2 роки тому

    Fantastic videos ❤️

  • @LthiagoR
    @LthiagoR Рік тому

    Amazing video!

  • @noxim_
    @noxim_ 8 років тому +18

    Ill crack numberphile account now.
    Hold my beer

    • @CircularEntertain
      @CircularEntertain 8 років тому +2

      Currently, for attacks on youtubers, the trend seems to be abusing a weakness with two factor auth. through social engineering. See H3h3.

    • @zirize
      @zirize 8 років тому

      The Other Other Yeah, they are using poor customer service of youtuber's mobile company. Issuing new sim cards then obtain youtuber's accounts.

    • @skate2late
      @skate2late 8 років тому +8

      "Hello my name is Tom Scott and I need a new SIM card"

  • @Packerr
    @Packerr 5 років тому +76

    14:47 Shoutout to ganjagoblin

    • @dishant8126
      @dishant8126 4 роки тому +1

      Ganja means Bald in Hindi so it reads as baldgoblin

    • @chebochebo7075
      @chebochebo7075 4 роки тому +9

      @@dishant8126 yea i bet thats what he had in mind

    • @princewilllucas3233
      @princewilllucas3233 3 роки тому

      There is nothing like impossible to hack in this digital world. For any hack related issue Contact @cybersquad047 on Instaqram, Cybersquad047@gmail.comthanks to them I found out the truth about my spouse

    • @codinghub3759
      @codinghub3759 3 роки тому

      @@dishant8126 I knew that... That was what I was thinking

  • @robertbrummayer4908
    @robertbrummayer4908 2 роки тому

    Awesome video!

  • @TheOurple
    @TheOurple 4 роки тому +1

    you deserve way more subs

  • @AJ-kj1go
    @AJ-kj1go 8 років тому +54

    Did computerphile stop asking tom scott to do videos for some reason?

    • @ericsbuds
      @ericsbuds 8 років тому +19

      he does have his own channel and probably takes up a lot of his time! check him out its pretty cool stuff.

    • @Chris-jo1zr
      @Chris-jo1zr 8 років тому +31

      I believe he said he'd not do too many more as he didn't know as much as some people on subjects.

    • @AJ-kj1go
      @AJ-kj1go 8 років тому +1

      Chris Gough
      ty

    • @mistermuffin710
      @mistermuffin710 8 років тому +3

      Ikr! I love his videos on Computerphile!

    • @FaelCacilhas
      @FaelCacilhas 8 років тому +4

      I actually stopped watching Computerphile so much and started watching his channel...

  • @17Haxor17
    @17Haxor17 8 років тому +5

    I like these kind of practical videos better than the theoretical ones.

  • @justjoeblow420
    @justjoeblow420 3 роки тому +2

    Aww I was hoping they would touch on the really fun stuff like using rainbow tables to speed things up even further. As funny as it sounds thank god for Rainbow tables it's the only reason why I can listen to any of the Audible audio books I've bought thanks to them not having an application for Linux.

  • @coachclement1
    @coachclement1 3 роки тому

    Great work

  • @forric23
    @forric23 5 років тому +3

    The question on everyone's mind is why at 6:03 he zoomed the camera out at the awkward moment youre scratching something suspicious. LOL - seriously great video's I have watched and shared a number of your videos and am a subsciber now! Keep up the great work!

  • @omegagamingalpha3253
    @omegagamingalpha3253 7 років тому +25

    CEO :some of our employees might want to play doom on the server.
    Engineer: *installs 4 Titan Xs*

  • @tz2014
    @tz2014 4 роки тому

    Hello sir, thank you for your videos, they are really informative and helpfully. can anyone share the link to playlist where i can access all of Dr. Mike's videos on security staffs, i will be gratefull

  • @KipIngram
    @KipIngram 2 місяці тому +1

    I do NOT have bad passwords. I've used a password vault for years and all of my passwords are generated by it and are around 16 characters long. My vault master password is over 20 characters long and uses digits, upper and lower case, and punctuation marks. I decided probably 10-12 years ago to get my password house in order, and it is in order.