A fifth of passwords used by federal agency cracked in security audit

TL;DR

Auditors then used a list of more than 1.5 billion words that included:- Dictionaries from multiple languages- US government terminology- Pop culture references- Publicly available password lists harvested from past data breaches across both public and private sectors- Common keyboard patterns (e.g., “qwerty”).“The significance of our findings regarding the Department’s poor password management is magnified given our high success rate cracking password hashes, the large number of elevated privilege and senior government employee passwords we cracked, and the fact that most of the Department’s HVAs did not employ MFA.”The most commonly used passwords, followed by the number of users, were:- Password-1234 | 478- Br0nc0$2012 | 389- Password123$ | 318- Password1234 | 274- Summ3rSun2020!The rigs themselves run multiple open source containers where we can bring up 2, 4, or 8 GPU and assign them tasks from the open source work distribution console.The vast majority—99.99 percent—of passwords cracked by the auditors complied with the department’s password complexity requirements, which mandate a minimum of 12 characters, and contain at least three of four character types consisting of uppercase, lowercase, digits, and special characters.“Even though a password [such as Password-1234] meets requirements because it includes uppercase, lowercase, digits, and a special character, it is extremely easy to crack,” the final report noted."

Like summarized versions? Support us on Patreon!