I have a reasonably strong password on my wifi (it looks something like "OwEs3PMY7yk6qwR4ic"). Is this crackable with this guy's setup in a couple of days?
I have a reasonably strong password on my wifi (it looks something like "OwEs3PMY7yk6qwR4ic"). Is this crackable with this guy's setup in a couple of days?
Also, they say "with a reasonably priced GPU cracking infrastructure, many systems can be cracked within a few days."
I take this to mean they're using something of the order of magnitude of a couple K80 instances on Google Cloud, which will cost $25 per day. By no means prohibitive if you want to try and crack one specific WiFi, but too expensive for wardriving etc.
Suppose Alice uses a 14 character password, each character chosen at random from the range [U+0021, U+007E] (e.g., the 94 printable ASCII characters above space). There are 4.21x10^27 or 2^91.8 possible passwords for Alice.
Bob, on the other hand, uses a 20 character password, also chosen at random, but Bob used a much smaller character set. He just used the 10 ASCII digits. There are 1x10^20 or 2^66.4 possible passwords for Bob. (Bob would need 28 digits for his password space to be as large as Alice's).
Bob's passwords come from a much smaller set, and so could be brute forced much faster--if the attacker knew that they only had to search that much smaller set. In most cases, though, the attacker will not know that.
But, a lot of people do use reduced character sets, so I'd expect brute force attackers to give some preference for searching those first--but how much? Would they be likely to find Bob's 20 character all numeric password ahead of Alice's 14 character all-94 password?
The correct answer is that it barely matters.
So an Alice password is worth 27.6 digits and if you went in order of entropy you'd try them after you try 27 digit passwords.
Let's say you think it's overwhelmingly likely that a password is Alice-style, maybe 99% likely. This suggests that you devote 1% of your processing power to Bob style. Instead of trying Alice-style passwords after you try 27 digit passwords, you will try them after... 25 digit passwords
Because the difficulty increases exponentially, devoting just a smidge of processing power to each different kind means that your progress goes roughly in order of increasing entropy.
And Bob's password will be cracked first, since "digits" is a very reasonable category to devote some computation to.
But you should look up how the default password generation algorithm is from the vendor / model you try to crack.
I make my wifipassword way longer by using my phonenumber
Rainbow tables are fairly useless though.
That's not an "everything's on fire" state of affairs, but it's plenty for a targeted attack against a specific domestic target to be feasible, since most home setups never rotate their password (and certainly aren't rotating it on a 2-day window).