• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Think your passwords are secure enough?

qubit

Overclocked quantum bit
Joined
Dec 6, 2007
Messages
17,865 (2.99/day)
Location
Quantum Well UK
System Name Quantumville™
Processor Intel Core i7-2700K @ 4GHz
Motherboard Asus P8Z68-V PRO/GEN3
Cooling Noctua NH-D14
Memory 16GB (2 x 8GB Corsair Vengeance Black DDR3 PC3-12800 C9 1600MHz)
Video Card(s) MSI RTX 2080 SUPER Gaming X Trio
Storage Samsung 850 Pro 256GB | WD Black 4TB | WD Blue 6TB
Display(s) ASUS ROG Strix XG27UQR (4K, 144Hz, G-SYNC compatible) | Asus MG28UQ (4K, 60Hz, FreeSync compatible)
Case Cooler Master HAF 922
Audio Device(s) Creative Sound Blaster X-Fi Fatal1ty PCIe
Power Supply Corsair AX1600i
Mouse Microsoft Intellimouse Pro - Black Shadow
Keyboard Yes
Software Windows 10 Pro 64-bit
About this, i never used that tehnology do they for instance rememebr the prints from multiple digits of your hand or just one. What if you are in an accident and you get your fingers burned and that is the only authentication method that you can access that phone tablet whatever ?
An iPhone or iPad will store up to 5 prints and also let you set an optional passcode as a backup.
 
Joined
Jan 5, 2006
Messages
17,793 (2.66/day)
System Name AlderLake / Laptop
Processor Intel i7 12700K P-Cores @ 5Ghz / Intel i3 7100U
Motherboard Gigabyte Z690 Aorus Master / HP 83A3 (U3E1)
Cooling Noctua NH-U12A 2 fans + Thermal Grizzly Kryonaut Extreme + 5 case fans / Fan
Memory 32GB DDR5 Corsair Dominator Platinum RGB 6000MHz CL36 / 8GB DDR4 HyperX CL13
Video Card(s) MSI RTX 2070 Super Gaming X Trio / Intel HD620
Storage Samsung 980 Pro 1TB + 970 Evo 500GB + 850 Pro 512GB + 860 Evo 1TB x2 / Samsung 256GB M.2 SSD
Display(s) 23.8" Dell S2417DG 165Hz G-Sync 1440p / 14" 1080p IPS Glossy
Case Be quiet! Silent Base 600 - Window / HP Pavilion
Audio Device(s) Panasonic SA-PMX94 / Realtek onboard + B&O speaker system / Harman Kardon Go + Play / Logitech G533
Power Supply Seasonic Focus Plus Gold 750W / Powerbrick
Mouse Logitech MX Anywhere 2 Laser wireless / Logitech M330 wireless
Keyboard RAPOO E9270P Black 5GHz wireless / HP backlit
Software Windows 11 / Windows 10
Benchmark Scores Cinebench R23 (Single Core) 1936 @ stock Cinebench R23 (Multi Core) 23006 @ stock
About this, i never used that tehnology do they for instance rememebr the prints from multiple digits of your hand or just one. What if you are in an accident and you get your fingers burned and that is the only authentication method that you can access that phone tablet whatever ?

My mom had this on her previous Acer laptop and it's on her new Asus laptop (didn't buy it because of it).
I tried it on her previous Acer laptop, could login with a finger scan, never used it permanently.
Nice feature but she doesn't use it.

I also think it's risky to use it since your fingerprints can get "damaged" from work/household work, winters-summers etc.
 

CAPSLOCKSTUCK

Spaced Out Lunar Tick
Joined
Feb 26, 2013
Messages
8,578 (2.11/day)
Location
llaregguB...WALES
System Name Party On
Processor Xeon w 3520
Motherboard DFI Lanparty
Cooling Big tower thing
Memory 6 gb Ballistix Tracer
Video Card(s) HD 7970
Case a plank of wood
Audio Device(s) seperate amp and 6 big speakers
Power Supply Corsair
Mouse cheap
Keyboard under going restoration
About this, i never used that tehnology do they for instance rememebr the prints from multiple digits of your hand or just one ? What if you are in an accident and you get your fingers burned and that is the only authentication method that you can access that phone tablet whatever ?




Jealous wife busted Foreign Office diplomat hubby’s affair after unlocking phone using thumbprint while he was ASLEEP
https://www.thesun.co.uk/news/16109...g-phone-using-thumbprint-while-he-was-asleep/
 
Joined
Oct 22, 2014
Messages
13,210 (3.81/day)
Location
Sunshine Coast
System Name Black Box
Processor Intel Xeon E3-1260L v5
Motherboard MSI E3 KRAIT Gaming v5
Cooling Tt tower + 120mm Tt fan
Memory G.Skill 16GB 3600 C18
Video Card(s) Asus GTX 970 Mini
Storage Kingston A2000 512Gb NVME
Display(s) AOC 24" Freesync 1m.s. 75Hz
Case Corsair 450D High Air Flow.
Audio Device(s) No need.
Power Supply FSP Aurum 650W
Mouse Yes
Keyboard Of course
Software W10 Pro 64 bit

qubit

Overclocked quantum bit
Joined
Dec 6, 2007
Messages
17,865 (2.99/day)
Location
Quantum Well UK
System Name Quantumville™
Processor Intel Core i7-2700K @ 4GHz
Motherboard Asus P8Z68-V PRO/GEN3
Cooling Noctua NH-D14
Memory 16GB (2 x 8GB Corsair Vengeance Black DDR3 PC3-12800 C9 1600MHz)
Video Card(s) MSI RTX 2080 SUPER Gaming X Trio
Storage Samsung 850 Pro 256GB | WD Black 4TB | WD Blue 6TB
Display(s) ASUS ROG Strix XG27UQR (4K, 144Hz, G-SYNC compatible) | Asus MG28UQ (4K, 60Hz, FreeSync compatible)
Case Cooler Master HAF 922
Audio Device(s) Creative Sound Blaster X-Fi Fatal1ty PCIe
Power Supply Corsair AX1600i
Mouse Microsoft Intellimouse Pro - Black Shadow
Keyboard Yes
Software Windows 10 Pro 64-bit
[QUOTE="P4-630, post: 3512315, member: 22154"I also think it's risky to use it since your fingerprints can get "damaged" from work/household work, winters-summers etc.[/QUOTE]
Yup, that happened to me a fair bit, making fingerprint authentication a little too "secure" for my liking. Had to fallback on the passcode.

@CAPSLOCKSTUCK the headline from our esteemed newspaper reads "green with envoy", lol. I wonder if they'll ever spot their cockup?
 
Last edited:

CAPSLOCKSTUCK

Spaced Out Lunar Tick
Joined
Feb 26, 2013
Messages
8,578 (2.11/day)
Location
llaregguB...WALES
System Name Party On
Processor Xeon w 3520
Motherboard DFI Lanparty
Cooling Big tower thing
Memory 6 gb Ballistix Tracer
Video Card(s) HD 7970
Case a plank of wood
Audio Device(s) seperate amp and 6 big speakers
Power Supply Corsair
Mouse cheap
Keyboard under going restoration
i would be very, very surprised if she is charged with anything......her "punishment" didnt befit her crime.



Perhaps he should have used a strong password using a strange collection of ch&rEcters
 
Joined
Jun 29, 2016
Messages
140 (0.05/day)
But who would store their biometric prints on an unsecured device? It is better to just use NFC chip or something like that that autmatically unlocks the system in proximity.
 

silentbogo

Moderator
Staff member
Joined
Nov 20, 2013
Messages
5,473 (1.44/day)
Location
Kyiv, Ukraine
System Name WS#1337
Processor Ryzen 7 3800X
Motherboard ASUS X570-PLUS TUF Gaming
Cooling Xigmatek Scylla 240mm AIO
Memory 4x8GB Samsung DDR4 ECC UDIMM
Video Card(s) Inno3D RTX 3070 Ti iChill
Storage ADATA Legend 2TB + ADATA SX8200 Pro 1TB
Display(s) Samsung U24E590D (4K/UHD)
Case ghetto CM Cosmos RC-1000
Audio Device(s) ALC1220
Power Supply SeaSonic SSR-550FX (80+ GOLD)
Mouse Logitech G603
Keyboard Modecom Volcano Blade (Kailh choc LP)
VR HMD Google dreamview headset(aka fancy cardboard)
Software Windows 11, Ubuntu 20.04 LTS
My mom had this on her previous Acer laptop and it's on her new Asus laptop (didn't buy it because of it).
I tried it on her previous Acer laptop, could login with a finger scan, never used it permanently.
Nice feature but she doesn't use it.

I also think it's risky to use it since your fingerprints can get "damaged" from work/household work, winters-summers etc.
On laptops there is a failover in most cases. I had both Acer and LG laptops with fingerprint reader, and both were based on AuthenTek capacitive reader.
The built-in software makes multiple scans of all 10 fingers during the initialization process, and you can log-in with either one (tested - works). Basically, if you cut/burn/lose one fingertip, you can always use the other ones.
I am not 100% sure, but you may be able to log-in with your toes =)
There was also a crappy, but interesting fingerprint-based password manager.


But who would store their biometric prints on an unsecured device? It is better to just use NFC chip or something like that that autmatically unlocks the system in proximity.
I know that old laptops with capacitive readers work in conjunction with TPM to encrypt data. Not so sure about phones.

NFC and Bluetooth are vulnerable to spoofing.
 
Joined
May 11, 2016
Messages
261 (0.09/day)
The main issue with pw and pw theft is that too many people take the bad approach of thinking up strong pw, but then using that same one everywhere. You really have to create unique passwords everywhere you use. Otherwise the security of it is only as strong as the weakest link, and there is always a weak security db/site out there getting hacked. So where people get in trouble is re-using the same strong password everywhere they login, and then for example a hobby site or similar they login to gets hacked and the hacker then has their pw and usually also email. Then it's simple for them to try those email/pw combos on big bank or shopping sites, etc. and far too often they are in. This is usually what happens (or keylogging), not so much brute force 1980's style anymore.
 
Joined
Feb 8, 2012
Messages
3,013 (0.68/day)
Location
Zagreb, Croatia
System Name Windows 10 64-bit Core i7 6700
Processor Intel Core i7 6700
Motherboard Asus Z170M-PLUS
Cooling Corsair AIO
Memory 2 x 8 GB Kingston DDR4 2666
Video Card(s) Gigabyte NVIDIA GeForce GTX 1060 6GB
Storage Western Digital Caviar Blue 1 TB, Seagate Baracuda 1 TB
Display(s) Dell P2414H
Case Corsair Carbide Air 540
Audio Device(s) Realtek HD Audio
Power Supply Corsair TX v2 650W
Mouse Steelseries Sensei
Keyboard CM Storm Quickfire Pro, Cherry MX Reds
Software MS Windows 10 Pro 64-bit
Brute forcing of passwords simply isn't a thing anymore and hasn't been for decades, with the obvious exception of random unsecured servers that the general public won't be accessing anyway.
You are assuming malicious individual has more incentive to hack your mail account than to gain remote desktop access admin account on a server that has huge amounts of bandwidth available ... the important illegal activities ultimately have to originate from a zombie machine.
Even if the most common way of "hacking" someone's account is still by reading the content of a post-it note stuck on his monitor, it doesn't mean that brute force method is suddenly less viable ... with faster networks it gets more viable, fooling the router's or server's anti attack heuristics also gets less challenging with all free VPNs and global networks of zombie machines. Think about it.
It's not like everything is on virtual machines in the cloud (yet) and separated in restricted access subnets ... internet is a colorful place
 

silentbogo

Moderator
Staff member
Joined
Nov 20, 2013
Messages
5,473 (1.44/day)
Location
Kyiv, Ukraine
System Name WS#1337
Processor Ryzen 7 3800X
Motherboard ASUS X570-PLUS TUF Gaming
Cooling Xigmatek Scylla 240mm AIO
Memory 4x8GB Samsung DDR4 ECC UDIMM
Video Card(s) Inno3D RTX 3070 Ti iChill
Storage ADATA Legend 2TB + ADATA SX8200 Pro 1TB
Display(s) Samsung U24E590D (4K/UHD)
Case ghetto CM Cosmos RC-1000
Audio Device(s) ALC1220
Power Supply SeaSonic SSR-550FX (80+ GOLD)
Mouse Logitech G603
Keyboard Modecom Volcano Blade (Kailh choc LP)
VR HMD Google dreamview headset(aka fancy cardboard)
Software Windows 11, Ubuntu 20.04 LTS
About bruteforce attacks: It is more viable now than it ever was. If a single machine cannot handle that kind of workload, you can always "employ" more compute power for cheap (or for free).
Few years ago there was an article on XAKEP.RU about using AWS for crypto-workload. Alternatively - botnets (a.k.a. multi-purpose supercomputer at your fingertips).
Since the OP has started with GPU applications in password hacking, then it is totally appropriate to mention fake BitCoin pools.

Back in a day there was also a distributed service for RainbowTable "mining" and another one for "sharing" (you upload a partial table ~100MB in size, and they let you decrypt few MD5 hashes for free by using their extensive library of multilingual mixed password hashes). Can't remember website names, but I don't think they even exist now.
 
Joined
Oct 17, 2012
Messages
9,781 (2.33/day)
Location
Massachusetts
System Name Americas cure is the death of Social Justice & Political Correctness
Processor i7-11700K
Motherboard Asrock Z590 Extreme wifi 6E
Cooling Noctua NH-U12A
Memory 32GB Corsair RGB fancy boi 5000
Video Card(s) RTX 3090 Reference
Storage Samsung 970 Evo 1Tb + Samsung 970 Evo 500Gb
Display(s) Dell - 27" LED QHD G-SYNC x2
Case Fractal Design Meshify-C
Audio Device(s) on board
Power Supply Seasonic Focus+ Gold 1000 Watt
Mouse Logitech G502 spectrum
Keyboard AZIO MGK-1 RGB (Kaith Blue)
Software Win 10 Professional 64 bit
Benchmark Scores the MLGeesiest
i have always found that instead of substituting letters for symbols, it always worked for me to just take a password like ....

1234, and change it to.

1Two3Four
or 0ne2thr33Four, etc..
 

Frick

Fishfaced Nincompoop
Joined
Feb 27, 2006
Messages
18,928 (2.86/day)
Location
Piteå
System Name Black MC in Tokyo
Processor Ryzen 5 5600
Motherboard Asrock B450M-HDV
Cooling Be Quiet! Pure Rock 2
Memory 2 x 16GB Kingston Fury 3400mhz
Video Card(s) XFX 6950XT Speedster MERC 319
Storage Kingston A400 240GB | WD Black SN750 2TB |WD Blue 1TB x 2 | Toshiba P300 2TB | Seagate Expansion 8TB
Display(s) Samsung U32J590U 4K + BenQ GL2450HT 1080p
Case Fractal Design Define R4
Audio Device(s) Line6 UX1 + some headphones, Nektar SE61 keyboard
Power Supply Corsair RM850x v3
Mouse Logitech G602
Keyboard Cherry MX Board 1.0 TKL Brown
VR HMD Acer Mixed Reality Headset
Software Windows 10 Pro
Benchmark Scores Rimworld 4K ready!
I wouldn't trust an Android device of any type, even the purest Nexus devices with my bank login credentials. iPhones and iPads seem to be more secure, with Apple's walled garden paying off here, but I'm still not sure how much I'd trust them.

*knocks on wood* We'll see if things break there. You can't do everything on the app, but most things. Six digit numerical code, the good thing is that the keypad is randomized (the numbers switch places, so you can't guess the code by looking at the entering of the code). And you need to authorize every device with your card. So far it's worked, but then I don't really know of the innee workings of the system.
 

Frick

Fishfaced Nincompoop
Joined
Feb 27, 2006
Messages
18,928 (2.86/day)
Location
Piteå
System Name Black MC in Tokyo
Processor Ryzen 5 5600
Motherboard Asrock B450M-HDV
Cooling Be Quiet! Pure Rock 2
Memory 2 x 16GB Kingston Fury 3400mhz
Video Card(s) XFX 6950XT Speedster MERC 319
Storage Kingston A400 240GB | WD Black SN750 2TB |WD Blue 1TB x 2 | Toshiba P300 2TB | Seagate Expansion 8TB
Display(s) Samsung U32J590U 4K + BenQ GL2450HT 1080p
Case Fractal Design Define R4
Audio Device(s) Line6 UX1 + some headphones, Nektar SE61 keyboard
Power Supply Corsair RM850x v3
Mouse Logitech G602
Keyboard Cherry MX Board 1.0 TKL Brown
VR HMD Acer Mixed Reality Headset
Software Windows 10 Pro
Benchmark Scores Rimworld 4K ready!
About this, i never used that tehnology do they for instance rememebr the prints from multiple digits of your hand or just one ? What if you are in an accident and you get your fingers burned and that is the only authentication method that you can access that phone tablet whatever ?

Dunno bout that, but I do know it's a hassle if the scanner stops working. It has happened to a bunch of friends of mine, and they have to RMA it.
 

Ahhzz

Moderator
Staff member
Joined
Feb 27, 2008
Messages
8,740 (1.48/day)
System Name OrangeHaze / Silence
Processor i7-13700KF / i5-10400 /
Motherboard ROG STRIX Z690-E / MSI Z490 A-Pro Motherboard
Cooling Corsair H75 / TT ToughAir 510
Memory 64Gb GSkill Trident Z5 / 32GB Team Dark Za 3600
Video Card(s) Palit GeForce RTX 2070 / Sapphire R9 290 Vapor-X 4Gb
Storage Hynix Plat P41 2Tb\Samsung MZVL21 1Tb / Samsung 980 Pro 1Tb
Display(s) 22" Dell Wide/24" Asus
Case Lian Li PC-101 ATX custom mod / Antec Lanboy Air Black & Blue
Audio Device(s) SB Audigy 7.1
Power Supply Corsair Enthusiast TX750
Mouse Logitech G502 Lightspeed Wireless / Logitech G502 Proteus Spectrum
Keyboard K68 RGB — CHERRY® MX Red
Software Win10 Pro \ RIP:Win 7 Ult 64 bit
.....

Back in a day there was also a distributed service for RainbowTable "mining" and another one for "sharing" (you upload a partial table ~100MB in size, and they let you decrypt few MD5 hashes for free by using their extensive library of multilingual mixed password hashes). Can't remember website names, but I don't think they even exist now.

I remember that!!!!
 
Joined
Aug 22, 2016
Messages
292 (0.10/day)
I am using a password locking software to lock the y most folders. Like not the ones that have the daily pics, docs etc but the ones like official transcripts, bank statements and other personal data. I first encrypt my files and then add them to the folder that has password lock. Do not need to lock again and again the folder, I just drag the files into it and it automatically locks them. And both of these features are in the same encryption software.
 
Joined
Feb 8, 2012
Messages
3,013 (0.68/day)
Location
Zagreb, Croatia
System Name Windows 10 64-bit Core i7 6700
Processor Intel Core i7 6700
Motherboard Asus Z170M-PLUS
Cooling Corsair AIO
Memory 2 x 8 GB Kingston DDR4 2666
Video Card(s) Gigabyte NVIDIA GeForce GTX 1060 6GB
Storage Western Digital Caviar Blue 1 TB, Seagate Baracuda 1 TB
Display(s) Dell P2414H
Case Corsair Carbide Air 540
Audio Device(s) Realtek HD Audio
Power Supply Corsair TX v2 650W
Mouse Steelseries Sensei
Keyboard CM Storm Quickfire Pro, Cherry MX Reds
Software MS Windows 10 Pro 64-bit
I am using a password locking software to lock the y most folders. Like not the ones that have the daily pics, docs etc but the ones like official transcripts, bank statements and other personal data. I first encrypt my files and then add them to the folder that has password lock. Do not need to lock again and again the folder, I just drag the files into it and it automatically locks them. And both of these features are in the same encryption software.
Since you like encrypting sensitive information, there are also email services like Proton Mail (https://protonmail.com/) that are completely encrypted: inbox is stored encrypted in the data center and communication is encrypted end-to-end through their web or mobile app ... in case you need a separate mail address for sensitive stuff (invoices, delivery statuses and such)
It uses (and maintains) Pretty Good Protection library for javascript
 
Last edited:
Top