Skip to content
PURPLEDUEL

Brute force and strong passwords: how they work and how to defend

Updated · 2 min read

A brute-force attack tries one password after another, thousands or millions of them, until one works. There is nothing clever about it: it works because so many passwords are short, predictable or reused. Understanding how an attacker thinks helps you choose better passwords and configure systems that resist.

The most common variants

Why length matters more than complexity

Each extra character multiplies the number of guesses needed. This is how many combinations exist for a truly random password using only lowercase letters (26 characters) or letters, digits and symbols (about 94 characters):

LengthLowercase onlyLetters, digits and symbols
6 charactersabout 309 millionabout 690 billion
8 charactersabout 209 billionabout 6 quadrillion
12 charactersabout 9.5×10¹⁶about 4.8×10²³
16 charactersabout 4.4×10²²about 3.7×10³¹

Note that these figures hold for truly random passwords. A password like Marco1985! has 10 characters, but it appears in every dictionary together with its variations and falls very quickly. A long, unusual passphrase (four or five unrelated words) or a randomly generated password from a manager is far better.

A worked example: what the defender sees

This is an invented excerpt of a service's sign-in log:

10:41:02 login failed   user=anna  ip=203.0.113.50
10:41:03 login failed   user=anna  ip=203.0.113.50
10:41:03 login failed   user=anna  ip=203.0.113.50
10:41:04 login failed   user=anna  ip=203.0.113.50
...
10:41:09 login success  user=anna  ip=203.0.113.50

Dozens of attempts within seconds from the same address, then a success: no human types that fast. It is the signature of a brute-force attack that worked, and the point where a good system should have reacted. (The address 203.0.113.50 belongs to a block reserved for documentation.)

How to defend

Keep reading