A long boring sentence beats a tricky password | Shahmaran
Environmental
A long boring sentence beats a tricky password
A long read
The password you hate might be the weak one
Picture two passwords. Which one is harder to crack?
Before / After
Tap to flip between the two passwords.
Tr0ub4dor&3
One is short with symbols. One is four plain words.
Most people pick the tricky one. It looks safe.
Your guess
Which password takes a computer LONGER to guess?
Sources
Bonneau, Bursztein, Caron, Jackson & Williamson (Google), "Secrets, Lies, and Account Recovery," WWW 2015 — a 19.7% one-guess hit rate on favourite food
Chick3nman (Team Hashcat), raw hashcat v6.2.6 benchmark on a single NVIDIA RTX 5090, published 2025-02-10 — MD5 220.6 GH/s, NTLM 340.1 GH/s, SHA-256 28.4 GH/s, bcrypt 304.8 kH/s at hashcat default work factor 5; independently reproduced on the hashcat forum. https://gist.github.com/Chick3nman/09bac0775e6393468c2925c1e1363d5c
Chick3nman, hashcat v6.2.6 RTX 4090 benchmarks — MD5 164.1 GH/s, NTLM 288.5 GH/s, bcrypt 184.0 kH/s. Supports the 100-billion-per-second figure and shows why the hash, not the character set, sets the speed. https://gist.github.com/Chick3nman/32e662a5bb63bc4f51b847bb422222fd
Correction to the existing source list: the entry reading '8-character minimum and a 15-character recommendation where a password stands alone' repeats the same inversion as the body copy. It should read that 15 characters is a requirement for single-factor use, with 8 applying only inside multi-factor use.
Google / Harris Poll Online Security Survey — fielded December 2018, 3,000 U.S. adults; 52% reuse across several accounts, 13% across all, 35% use a different password everywhere. The current source note omits the population and field date. https://services.google.com/fh/files/blogs/google_security_infographic.pdf
Google / Harris Poll Online Security Survey (2019) — 52% reuse a password across several accounts, 13% across all of them
Government of Canada, August 2020 — 9,041 GCKey accounts compromised and ~5,500 CRA accounts targeted by credential stuffing
Hashcat project benchmarks — GPU guess rates against MD5 and NTLM
Have I Been Pwned front page, checked 2026-08-09 — 17,777,846,158 pwned addresses across 1,026 pwned websites. Replaces 'over 15 billion / over 900 sites'. https://haveibeenpwned.com/
Have I Been Pwned, Pwned Passwords page — '18B+' monthly requests, >99.9% cache hit ratio, 335 edge locations. Supports the existing 18-billion-checks claim. https://haveibeenpwned.com/Passwords
Have I Been Pwned, Synthient Credential Stuffing Threat Data (loaded 5 November 2025) — 1,957,476,021 unique email addresses, 1.3 billion passwords, 625 million previously unseen. Supports the existing batch figures. https://haveibeenpwned.com/Breach/SynthientCredentialStuffingThreatData
Hive Systems methodology note — the 2024 table ran at bcrypt work order 5 and had to be re-run at work order 10 to compare with 2025 and 2026. Needed to explain why the old cells cannot be carried forward.
Hive Systems, 2026 Password Table (published July 2026) — 16 rented RTX 5090 GPUs, bcrypt work factor 10; 8 characters with all four character types = 132 years (164 in 2025, 225 in 2024 re-run at the same work factor); 8 lowercase-only = ~2 weeks. Replaces the 2024 table currently cited. https://www.hivesystems.com/blog/are-your-passwords-in-the-green
Hive Systems, annual password table — bcrypt crack times measured on 12 RTX 4090 GPUs
NIST SP 800-63B-4, Digital Identity Guidelines, published 26 August 2025, section 3.1.1.2 — 15 characters is a SHALL for single-factor passwords; 8 characters applies only within multi-factor use; maximum of at least 64; no composition rules; no periodic resets; blocklist screening. https://pages.nist.gov/800-63-4/sp800-63b.html
NIST Special Publication 800-63B-4, Digital Identity Guidelines (finalised August 2025) — no composition rules, no scheduled resets, breach-list screening, 8-character minimum and a 15-character recommendation where a password stands alone
Note: kzero.com, huntress.com and breachsense.com currently appear as inline citations in the body but are absent from source_references. All three are security vendors and should be dropped rather than promoted into the list.
Randall Munroe, xkcd 936 "Password Strength", and explainxkcd — the 28-bit vs 44-bit comparison and "correct horse battery staple"
Thomas, Doerfler et al. (Google, New York University, UC San Diego), 2019 — SMS codes blocked 100% of automated and 96% of bulk-phishing attacks; on-device prompts 100%/99%; security keys 100% of all three
Troy Hunt, Have I Been Pwned — leaked-credential corpus and the k-anonymity password check
Read end to end and corrected: August 9, 2026. Numbers checked: August 9, 2026.