If your passwords are less than 8 characters long, change them immediately, a new study says (2024)

Short and simple passwords can be cracked in a matter of seconds. Long and complicated ones? Trillions of years.

That's according to a recent study from Hive Systems, a cybersecurity company based in Richmond, Virginia, which breaks down just how long it would likely take the average hacker to crack the passwords safeguarding your most important online accounts.

The findings suggest that even an eight-character password — with a healthy mix of numbers, uppercase letters, lowercase letters and symbols — can be cracked within eight hours by the average hacker. Anything shorter or less complex could be cracked instantly, or within a few minutes, by any hacker who knows what they're doing, even if they're only using fairly basic equipment.

Meanwhile, a password that's 18 characters in length – and which uses a mix of numbers, lowercase and uppercase letters, and symbols – could take up to 438 trillion years for the average hacker to crack, according to Hive Systems.

The company compiled a color-coded graph to illustrate how quickly different passwords could be hacked, depending on their length and use of varied characters, and how those times have accelerated since 2020 thanks to faster technology:

The findings back up the advice of experts like the National Institute of Standards and Technology, which also suggests choosing long, complex passwords with at least eight characters.

For the study, Hive Systems ran tests to determine how quickly the average hacker – meaning someone using consumer-grade equipment, including a desktop computer with "a top-tier graphics card" – can crack passwords of different lengths and complexities.

In a blog post, company researchers explain how the process of cracking your passwords can work. It starts with a process called "hashing," an algorithmically driven process websites use to disguise your stored passwords from hackers.

If you plug the word "password" into one commonly-used hashing software, called MD5, you'll get this string of characters: "5f4dcc3b5aa765d61d8327deb882cf99." The idea is that if hackers break into a website's server to find lists of stored passwords, they'll only see hashed jumbles of letters and numbers.

You shouldn't, of course, use "password" as your password. In fact, it's one of the most common passwords that end up leaked on the dark web.

If your passwords are less than 8 characters long, change them immediately, a new study says (1)

VIDEO2:4602:46

The best financial advice I learned from my time on Wall Street

Hashed passwords are irreversible, because they're created with one-way algorithms. But hackers can make lists of every possible combination of characters on your keyboard, and then hash those combinations themselves using the most commonly-used software programs. At that point, hackers only have to search for matches of the hashed passwords on their list to determine your original passwords.

It's a complicated process, but one that can easily be pulled off by any knowledgeable hacker with consumer-grade equipment, Hive Systems notes. That's why your best defense is using the sort of long, complicated passwords that take the longest to crack.

The report also strongly recommends not recycling passwords for multiple websites. If you do that, and hackers are able to crack your password for one website, then "you're in for a bad time," the company writes.

Understandably, you might not want to remember 18-character passwords each time you log into an online account. After all, a password that takes trillions of years to crack isn't very useful if it also takes you a few million years to remember.

But even a password with 11 characters – again, using a mix of numbers, uppercase and lowercase letters, and symbols – could still take hackers 34 years to crack, Hive Systems estimates. And that's certainly better than eight hours or less.

CORRECTION: An earlier version of this article misstated that Hive Systems used a Security.org tool to complete its 2022 study. In fact, Hive Systems used the tool for an earlier study in 2020, not the most recent version.

Sign up now: Get smarter about your money and career with our weekly newsletter

Don't miss:

These are the 20 most common passwords leaked on the dark web — make sure none of them are yours

'These 9 biggest password mistakes will get you in trouble,' warns fraud expert and ex-con artist

If your passwords are less than 8 characters long, change them immediately, a new study says (2)

VIDEO8:5408:54

This former Wall Street analyst now lives on $53 dollars a day in France

If your passwords are less than 8 characters long, change them immediately, a new study says (2024)

FAQs

What is an 8 character long password? ›

A: An 8 characters password example could be something like UBm5q9EF. It should contain a combination of at least 8 characters, including lowercase letters, uppercase letters, numbers and special symbols. Using a strong and unique password like this can help keep your information safe from hackers.

Is an 8 character password enough? ›

After all, it is one of 6.1 quadrillion combinations, and would take a reasonably fast computer nearly a year to crack. That password, however, is no longer secure enough, thanks to human behavior and technology. For starters, humans struggle to retain more than seven numbers in short-term memory.

Should password length be at least 8 characters? ›

Best practices. Set minimum password length to at least a value of 8. If the number of characters is set to 0, no password is required. In most environments, an eight-character password is recommended because it's long enough to provide adequate security and still short enough for users to easily remember.

How long does it take to crack a password of characters? ›

BeCyberSmart: How Fast Can a Hacker Break YOUR Password?
No. of CharactersNumbers OnlyLowercase Letters
No. of Characters 16Numbers Only 1 hourLowercase Letters 713 years
No. of Characters 17Numbers Only 14 hourLowercase Letters 18k years
No. of Characters 18Numbers Only 6 daysLowercase Letters 481k years
12 more rows
Oct 6, 2023

What does 8 character long mean? ›

you have been asked to enter a password of your choosing,” 8 characters long” is asking you to choose 8 of letters of the alphabet made up of lower case and upper case, a number, the password would look as follow. MOntbLanc 19. 3 upper case letters 7 lower case letter two numbers.

What is an example of a hard password? ›

Password: m#P52s@ap$V

It's strong, long, and difficult for someone else to guess. It uses more than 10 characters with letters (both uppercase and lowercase), numbers, and symbols, and includes no obvious personal information or common words.

What is a good password length? ›

A strong password is: At least 12 characters long but 14 or more is better. A combination of uppercase letters, lowercase letters, numbers, and symbols.

What is the best password length 2024? ›

A 12-character password is extremely safe because they are impossible to guess for a person and is considered the best safeguard against threat actors. Combining lowercase letters, uppercase letters, numbers, and symbols will make it much better for you.

How fast can passwords be hacked? ›

A simple eight-character password can be cracked in only 37 seconds using brute force but it takes over a century to crack a 16-character one.

What's a special character for a password? ›

a minimum of 1 special character: ~`! @#$%^&*()-_+={}[]|\;:"<>,./? at least 1 upper case, numeric, and special character must be EMBEDDED somewhere in the middle of the password, and not just be the first or the last character of the password string.

Why does my password have to be 8 characters? ›

With computer power increasing all the time, the minimum required password length is a moving target that's only going to go up. But for today's computing power, eight is the minimum number of characters that the NIST recommends.

What is an example of a 8 20 character password? ›

A: An example of a password that has 8-20 characters can be “it3XE@ha2*”. It should include a combination of uppercase letters, lowercase letters, numbers, and symbols or special characters.

What is an example of an 8 character password? ›

Strong Password 8 Characters
Password Length:
Include Lowercase Characters:(e.g. abcdef)
Include Uppercase Characters:(e.g. ABCDEF)
Include Numbers:(e.g. 123456)
4 more rows

Is it hard to crack a password? ›

Password Cracking: FAQs

The longer and more varied your password is, the harder it will be for hackers to crack it. A 12-character password that only uses numbers will take just a second to crack, but 14-character passwords that use numbers, symbols, upper case, and lower case letters can take millions of years.

How long is an unbreakable password? ›

Make It Long & Memorable

You should make your password long and memorable instead. That means using a phrase with at least 8 characters. Longer is better when it comes to passwords. A 32-character password has the potential to be much stronger than an 8-character password.

What is an example of a strong 8 to 20 character password? ›

Q: What is an example of an 8 20 characters password? A: An example of a password that has 8-20 characters can be “it3XE@ha2*”. It should include a combination of uppercase letters, lowercase letters, numbers, and symbols or special characters.

What is an 8 to 16 character password example? ›

A: An 8 to 16 character password example is a password that is made up of 8 to 16 characters, usually a combination of letters, numbers, and/or symbols. Strong passwords can help secure your accounts and information from unwanted access. Examples include “A1b%#A5t” or “ML7&y*F6”.

What is an example of a 8 to 13 character long password? ›

A: There are many types of passwords that can be 8 to 13 characters long. Some examples include: “m83@chr1s!”, “PuppyLuv36”, “FunkyFish8”, or “Sparkles!!!”. It's important to use a combination of uppercase and lowercase letters, numbers, and symbols to make your password more secure.

What is Type 8 password? ›

Type 8. Type 8 passwords are what Type 4 was meant to be, an upgraded Type 5! Type 8 is hashed using PBKDF2, SHA-256, 80-bit salt, 20,000 iterations. While this is good, it is still vulnerable to brute-forcing since AES is easy to implement in (GPU) graphics cards.

Top Articles
Allow An App Through Firewall Greyed Out Windows 11
Support
Frases para un bendecido domingo: llena tu día con palabras de gratitud y esperanza - Blogfrases
Exclusive: Baby Alien Fan Bus Leaked - Get the Inside Scoop! - Nick Lachey
Le Blanc Los Cabos - Los Cabos – Le Blanc Spa Resort Adults-Only All Inclusive
Gabrielle Abbate Obituary
Parks in Wien gesperrt
Corporate Homepage | Publix Super Markets
Jessica Renee Johnson Update 2023
DIN 41612 - FCI - PDF Catalogs | Technical Documentation
DoorDash, Inc. (DASH) Stock Price, Quote & News - Stock Analysis
Fool’s Paradise movie review (2023) | Roger Ebert
Craigslist Free Stuff Santa Cruz
Idaho Harvest Statistics
Charter Spectrum Store
Roof Top Snipers Unblocked
Army Oubs
Daylight Matt And Kim Lyrics
Persona 5 Royal Fusion Calculator (Fusion list with guide)
Popular Chinese Restaurant in Rome Closing After 37 Years
Understanding Gestalt Principles: Definition and Examples
Essence Healthcare Otc 2023 Catalog
Devotion Showtimes Near Regency Buenaventura 6
Strange World Showtimes Near Savoy 16
Snohomish Hairmasters
2023 Ford Bronco Raptor for sale - Dallas, TX - craigslist
Maine Racer Swap And Sell
Combies Overlijden no. 02, Stempels: 2 teksten + 1 tag/label & Stansen: 3 tags/labels.
Kaliii - Area Codes Lyrics
Helpers Needed At Once Bug Fables
Ff14 Sage Stat Priority
The value of R in SI units is _____?
"Pure Onyx" by xxoom from Patreon | Kemono
Hattie Bartons Brownie Recipe
Suspect may have staked out Trump's golf course for 12 hours before the apparent assassination attempt
RUB MASSAGE AUSTIN
How Much Is Mink V3
Crystal Mcbooty
Mars Petcare 2037 American Italian Way Columbia Sc
Firestone Batteries Prices
Cocorahs South Dakota
John Wick: Kapitel 4 (2023)
Air Sculpt Houston
Menu Forest Lake – The Grillium Restaurant
Mega Millions Lottery - Winning Numbers & Results
Www.homedepot .Com
Smoke From Street Outlaws Net Worth
Tanger Outlets Sevierville Directory Map
28 Mm Zwart Spaanplaat Gemelamineerd (U999 ST9 Matte | RAL9005) Op Maat | Zagen Op Mm + ABS Kantenband
Latest Posts
Article information

Author: Rubie Ullrich

Last Updated:

Views: 6485

Rating: 4.1 / 5 (52 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Rubie Ullrich

Birthday: 1998-02-02

Address: 743 Stoltenberg Center, Genovevaville, NJ 59925-3119

Phone: +2202978377583

Job: Administration Engineer

Hobby: Surfing, Sailing, Listening to music, Web surfing, Kitesurfing, Geocaching, Backpacking

Introduction: My name is Rubie Ullrich, I am a enthusiastic, perfect, tender, vivacious, talented, famous, delightful person who loves writing and wants to share my knowledge and understanding with you.