Hashcat 6 with 8 x 2080ti cracks 8-character passwords in 2:30h on benchmarks
twitter.com
twitter.com
Also besides using a longer password, is there anything else that can be done to harden my passwords?
This is partly due to the complexity of calculating hashes being multiplicative with the password length, so they limit password length to prevent dos.
Hash algorithms or password hash algorithms? Because if the former I'd completely disagree, it would be closer to hundreds of years with a modern algorithm like Argon or even old stalwarts like Bcrypt with higher cost parameters.
The twitter statement is ridiculous, password length isn't the problem here, it's poorly secured credentials, was under the impression that NTLM was deprecated anyway?
Edit: Going off this benchmark[0] of 19000 H/s for a single 2080 crunching bcrypt. The keyspace for alphanumeric(62) + password symbols(23) with 8 characters = 85^8 = 2.72 x 10^15
@19000 H/s it will take 143416065810 seconds to go through every permutation. So around 4547 years worst case scenario. Add 7 more GPU's like in the OP's rig and that's 568 years.
The birthday problem doesn't apply here to finding a _specific password_ so on average looking at 284 years with 8x 2080 GPU's.
All modern algo's from the last Password Hashing Competition were designed to be memory hard (or at least offer it as a parameter) to resist GPU attacks and would be pushing these numbers up a magnitude or two.
8 character passwords aren't dead.
[0] https://gist.github.com/Chick3nman/d03c0d696699af2886c340425...