Free TrueCrypt Hard Drive Password Cracking
16s.us
16s.us
What qualifies as a "strong password" against such a tool?
"lua ham purple day girl"
The challenge with primary authentication passwords is that users typically cannot use a password manager or generator to recall the password and thus must be able to recall something that they can easily type and end-up selecting weak passwords. There are some exceptions to this (yubikey, etc) but most normal users don't or cannot use them for various reasons, so go with a nice pass phrase like the one above.
Like:
Cats and cows eat 200 tables a day.
The grape is 14 shades of orange. correct horse battery stapleA very long time. You're still looking at a total of 3-5 words you need to guess (9-25 characters based on 3-5 letters per word), in the right combination, and assuming all words are English or popular colloquialisms...
("greatly reducing" is still not going to make brute forcing a realistic choice).
It would still take a very long time but remember we're not iterating by character anymore. Each word is a 'character' and our alphabet is the english dictionary.
So for the example above, we have to guess 5 slots in the passphrase and each slot has [number of words in english dict] possibilities. And also we'd probably start guessing assuming 2 word passphrases and have to exhaust all of 2, 3 and 4 before we start guessing 5 word combinations.
So how rusty is your combinatorics? :)
Essentially it just tries to open the volume with many passwords in quick succession. So there isn't a vulnerability in Truecrypt itself, and complex / long passwords are unlikely to be found with this tool.
A good encryption scheme uses a slow hashing scheme and salt to defeat such attacks.
And for slow hashing schemes that is a fair point, but when you're looking at file decryption, there is nothing to stop parallel attempts happening at once on different machines. Also TC does support using cascading ciphers which can help to slow it down.
Note: I'm not an expert in Cryptography by any means, but this is my current understanding.
The key that is used to decrypt the hard disk is stored inside an area that is encrypted with the passphrase and/or keyfiles. That may use a different algorithm than the actually OTF encryption to the rest of the disk. Thus, you can use a short key with a LONG hash time and protect a LONG key with a short encryption time and voila.
I mean, that's how this service works anyway; you send it the volume header and it attempts to crack it. If it can read the contents of the header, then you can read out the key used to encrypt/decrypt the volume itself.