
That question is very often asked. First, you must remember that the easier a password is (or the shorter it is) the easier it is to crack. The problem is that millions of hackers are using thousands of computers simultaneously for only one purpose: guessing your password! Their computers try every characters combination, trying to access your multiple accounts, subscriptions, services, and apps, …
Considering the fact that as of today, a single computer is able to test 1 million passwords per second (yes!), let's have a look at the following comparison table to understand what type of passwords are weak, and what are the safer ones. The time required to crack a password varies according to both the password length and complexity.
The following table will give you a valuable advice in evaluating if your choices are making you vulnerable, or well-protected.
| If your password length is… | …and using… | …it can be cracked in : |
|---|---|---|
| 6 characters | Only lowercase characters | 20 seconds |
| 6 characters | Only UPPERCASE characters | 20 minutes |
| 6 characters | Uppercase + lowercase Letters, numbers, symbols | 10 hours |
| 7 characters | Only lowercase characters | 8 minutes |
| 7 characters | Only UPPERCASE characters | 17 hours |
| 7 characters | Uppercase + lowercase Letters, numbers, symbols | 3 days |
| 8 characters | Only lowercase characters | 3 hours |
| 8 characters | Only UPPERCASE characters | 5 weeks |
| 8 characters | Uppercase + lowercase Letters, numbers, symbols | 10 years |
| 9 characters | Only lowercase characters | 3 days |
| 9 characters | Only UPPERCASE characters | 5 years |
| 9 characters | Uppercase + lowercase Letters, numbers, symbols | 900 years |
| 10 characters | Only lowercase characters | 3 months |
| 10 characters | Only UPPERCASE characters | 200 years |
| 10 characters | Uppercase + lowercase Letters, numbers, symbols | 80 millenia |
| 11 characters | Only lowercase characters | 5 years |
| 11 characters | Only UPPERCASE characters | 10 millenia |
| 11 characters | Uppercase + lowercase Letters, numbers, symbols | 7000 millenia |
| 12 characters | Only lowercase characters | 100 years |
| 12 characters | Only UPPERCASE characters | 700 millenia |
| 12 characters | Uppercase + lowercase Letters, numbers, symbols | 500 000 millenia |
That table should warn you about the high risks of using a simple password. However, we have to complement it with one important side-note:
These data apply to an attack being carried out with ONLY ONE mid-sized "standard" computer, as of the state of 2019 CPU's average clock (e.g. Intel Core i5). But determined attackers will use specially crafted computers harnessing the power of several dozens of GPU (Graphical Processing Units), that are far better than classic CPU's in dealing with the mathematical operations such an attack implies. As a result, your 8 characters password would not take 10 years to be guessed, but, for example, only 6 hours !
However, as the majority of today attacks are not single-threaded, but performed with several tens, hundreds or even thousands of computers simultaneously, it divides the required time significantly. This situation puts a large processing power into hackers hands, thus dividing by 10, 100, 1000 (or even more) the time taken to break down your passwords.
So, instead of using the letter "a", you could use "â", or even better, use "Ä". Your password will remain memorable to you, but will require much more efforts to be guessed by the bad boys!
If you are using a short and weak password, you should consider upgrading it to a safer one, by using our free high-level password generator and following our 10 tips for a strong and secure password, to put your data in security right now.
If you prefer choosing your password by yourself without the help of any generator, be sure to read our Top 10 mistakes you must totally avoid in order to beef it up.
You must be aware that not all passwords are cracked or guessed by a remote computer. There are many other numerous ways of stealing your passwords or login credentials that you should be aware of.
And always remember that no password is Invulnerable: you must change it regularly to ensure you are completely annihilating hackers efforts to zero, forcing them to start a new guessing sequence. Security is a cat and mouse game, so be sure to be the smartest mouse!
Every time a password is stolen, it is not by chance: it is always the result of either a long and automated computer-driven work, or a methodical and insidious human action. Knowing where the threat comes from will help you improve your daily practices
Even if your passwords are all strong and regularly changed, Brute-force attacks are a plague, because they abuse your system resources constantly, even when they fail. Discover how to detect, slow-down and circumvent such attacks.
NOTE: Your changes will be applied from the next page you will visit/load.
By using this website, you consent that we use technologies such as anonymous statistics and cookies to improve your browsing experience on our site, customise content and advertising, and analyse our traffic. This anonymous information may be shared with our trusted social media, advertising and analytics partners.