Passwords
Passwords are rarely stolen directly: mostly they are guessed after a leak from some site. The film follows that path from a site's database to someone else's mailbox and shows what breaks it.
As text
The same as the films: every shot and its text. You can copy the text and give it to your own assistant along with your question.
Passwords
To recognize you, a site has to check your password somehow. It does not need to keep the password itself for that, and usually it does not: at sign-up the password goes through a hash function, and only the result, the hash, is written to the database. The function works one way: getting the hash from a password is easy, getting the password from the hash is not. At login the site hashes what you typed and compares it with what is in the database.
Suppose the database is stolen. Whoever has it now holds email addresses and hashes, but not passwords. A password cannot be recovered from its hash, but the attack can run the other way: take likely passwords, hash each one and look for a match in the stolen database. So it is more accurate to say that in such a leak passwords are not broken but guessed.
The guessing runs on the attacker's computer, not on the site, so no limit on login attempts applies. The program works through dictionaries, passwords from earlier leaks and common combinations such as a city name plus a year. It tries billions of candidates, so short and predictable passwords are found first.
A password's strength is the number of candidates an attacker has to try. A keyboard has about ninety-five characters, and each extra random character multiplies that number by ninety-five. The practical consequence: length matters more than swapping letters for lookalike symbols, because the program checks those swaps too. Five random words give a number of candidates twenty digits long, and they are easier to remember than eight random characters.
The guessed pair of address and password is then tried on other services: email, the bank, cloud storage. This is automated too and takes minutes. If the password is the same everywhere, a leak from a small online shop opens everything else as well. Your protection is then only as good as the weakest site you have signed up to.
So every site needs its own password, long and random. Nobody can remember dozens of those, and a password manager takes over the job. You keep one master password, and the manager itself is best protected with a second factor as well. Then a leak from one site costs one password, and you know which one.
You can check whether your address has turned up in known leaks on the Have I Been Pwned site. If it has, change the password on that site and everywhere you reused it. The next film is about the second factor: what it adds to a password and how its kinds differ.
Next
- Second factor · Security