Chart indicating how strong various passwords are.
@kibcol1049 What interval between entering successive passwords is assumed in this analysis? Does it account for the lockout for a certain amount of time which is often experienced after successive incorrect passwords are entered?

@dissident @kibcol1049 https://www.hivesystems.com/blog/are-your-passwords-in-the-green

"The implied attack assumes that MFA is not used or has been bypassed. If you can get access to download the encrypted database, like what happens with most password databases that are stolen, you don’t need to deal with MFA (or those pesky password lockouts) when making attempts thereafter."

The 2025 Hive Systems Password Table Is Here - Passwords Are Easier to Crack Than Ever

Passwords that felt secure a year ago might not hold up in 2025. Hive Systems’ updated Password Table reveals just how much faster hackers can break into accounts today. See the latest cracking times and find out if your passwords are still safe while downloading your copy.

Hive Systems
@placebo @kibcol1049 So this only refers to accessing data that's been encrypted with a password, not to accessing say an online account?
@dissident @placebo @kibcol1049 No, it refers to being able to get your hands on a one-way encrypted database with passwords and then figuring out what the password for a certain user account, in order to use that password on either the same or another site.
@ahltorp @dissident @placebo @kibcol1049
I like this one, which is more generic...
@davep @ahltorp @dissident @placebo @kibcol1049 I like yours because n months seems a moderate (yellowish) concern. OP’s color choices seem to be fussing similarly over tens-of-thousands of years.
@InkomTech @davep @ahltorp @dissident @placebo @kibcol1049 Yeah, I really don't understand why 28k years is any more of a concern than 280k years. The only way that makes sense to me is if you're concerned about the possibility of someone using hardware 5,000 times this powerful, at which point one is reduced to a bit of a marathon while the other remains wildly impractical.
@ahltorp @dissident @placebo @kibcol1049
It would be nice if the Hive graphic showed what the number of guesses per second was for each year too. That would make the one I use even more useful.