Brute force and strong passwords: how they work and how to defend
A brute-force attack tries one password after another, thousands or millions of them, until one works. There is nothing clever about it: it works because so many passwords are short, predictable or reused. Understanding how an attacker thinks helps you choose better passwords and configure systems that resist.
The most common variants
- Pure brute force: tries every possible combination of characters. Very slow on long passwords, quick on short ones.
- Dictionary attack: tries common words, names, dates and the most-used passwords of all time (
123456,password,qwerty), with small variations such asPassword1!. - Password spraying: a single very common password tried against a great many accounts, to stay under lockout thresholds.
- Credential stuffing: uses email and password pairs stolen from another site, counting on people reusing the same password everywhere.
Why length matters more than complexity
Each extra character multiplies the number of guesses needed. This is how many combinations exist for a truly random password using only lowercase letters (26 characters) or letters, digits and symbols (about 94 characters):
| Length | Lowercase only | Letters, digits and symbols |
|---|---|---|
| 6 characters | about 309 million | about 690 billion |
| 8 characters | about 209 billion | about 6 quadrillion |
| 12 characters | about 9.5×10¹⁶ | about 4.8×10²³ |
| 16 characters | about 4.4×10²² | about 3.7×10³¹ |
Note that these figures hold for truly random passwords. A password like Marco1985! has 10 characters, but it appears in every dictionary together with its variations and falls very quickly. A long, unusual passphrase (four or five unrelated words) or a randomly generated password from a manager is far better.
A worked example: what the defender sees
This is an invented excerpt of a service's sign-in log:
10:41:02 login failed user=anna ip=203.0.113.50
10:41:03 login failed user=anna ip=203.0.113.50
10:41:03 login failed user=anna ip=203.0.113.50
10:41:04 login failed user=anna ip=203.0.113.50
...
10:41:09 login success user=anna ip=203.0.113.50
Dozens of attempts within seconds from the same address, then a success: no human types that fast. It is the signature of a brute-force attack that worked, and the point where a good system should have reacted. (The address 203.0.113.50 belongs to a block reserved for documentation.)
How to defend
- Long, unique passwords for every service, created and stored by a password manager, so one leak does not open the others.
- Multi-factor authentication. With a second factor, a guessed password is not enough on its own. See the guide to MFA and passkeys.
- Limit attempts (rate limiting): temporary lockouts that grow longer, alerts and, after too many failures, an additional check. Without letting anyone lock another person's account at will.
- Store passwords as slow, salted hashes (Argon2id, bcrypt, scrypt) and never in clear text: the salt makes precomputed hash tables (rainbow tables) useless.
- Generic error messages: "invalid credentials", without saying whether the username or the password was wrong. Otherwise you hand attackers a list of existing users.
- Change factory-default credentials on routers, cameras and admin panels: lists of default passwords are public.
- Monitor: alerts for bursts of failed logins and for sign-ins from unusual places or times. You can also check whether your email appears in known breaches on a service such as Have I Been Pwned.