Live data from Hacker News

Show HN: I Dedicated 4 Years to Mastering Offline Password Cracking

news.ycombinator.com

21–30 of 66 posts

Re: Show HN: I Dedicated 4 Years to Mastering Offline Password Cracking

#21

There’s a reason there are no books about this, because most people are not interested in cracking local/offline passwords. In fact, the people most interested in password cracking are usually criminals. But good luck with the book. It’s just not a hugely in demand topic.

The reason is, that using hashcat is not complicated for people who have linux experience and the amount of people wanting to crack a password is probably not that high.

Otherwise you do find plenty of people on YT walking you through hashcat. The first YT Video alone has 7 Million views: "how to HACK a password // password cracking with Kali Linux and HashCat"

I wish him luck, great drive to do this, i hope it works out well enough, books are just in general not easy to sell.

Re: Show HN: I Dedicated 4 Years to Mastering Offline Password Cracking

#22

when i was running 150k amd gpus... i really wanted to use the cluster to run hashcat to help people recover lost things. i couldn't convince management that that was a profitable business to run.

> help people recover lost things You mean "lost things" in quotes. Management may have been more concerned about jail time.

Plenty of valid reasons to recover lost things and not just 'lost things'.

Re: Show HN: I Dedicated 4 Years to Mastering Offline Password Cracking

#23

There’s a reason there are no books about this, because most people are not interested in cracking local/offline passwords. In fact, the people most interested in password cracking are usually criminals. But good luck with the book. It’s just not a hugely in demand topic.

When I lived in Adelaide, Australia 2006 or 2007, flexible-neck LED lamps that you plugged into an USB port to have light on your keyboard (backlit keyboards were not the norm on laptops) were a novelty item.

People simply didn't /know/ about them/that they existed at all.

I went to a computer/electronics shop in town and asked for them.

The guy told me: "We don't stock them because people don't ask for them."

Re: Show HN: I Dedicated 4 Years to Mastering Offline Password Cracking

#24

Earlier quoted context omitted.

> help people recover lost things You mean "lost things" in quotes. Management may have been more concerned about jail time.

Plenty of valid reasons to recover lost things and not just 'lost things'.

Yes that was what i was implying.

Re: Show HN: I Dedicated 4 Years to Mastering Offline Password Cracking

#25
This is a really impressive project, especially starting at 14. The point about there being no single comprehensive resource rings true, I've tried to learn about password security before and always ended up jumping between five different tabs just to understand one concept.

Re: Show HN: I Dedicated 4 Years to Mastering Offline Password Cracking

#26

relevant https://en.wikipedia.org/wiki/2022_LastPass_data_breach probably a lot of ppl lost crypto this way.

I don't think so. Every lastpass vault is encrypted by the users password. Wikipedia states that there were some field unencrypted, sure, but not the critical data. More people probably lost crypto by forgetting their passwords like a friend of mine. 10k gone

This is misleading, if not false, for a sufficient many accounts, particularly early adopters of LastPass.

https://en.wikipedia.org/wiki/2022_LastPass_data_breach#Impa...

Many early vaults had an insufficient number of rounds, and though the new account default was upgraded over time, the old vaults never were. So longer time customers were very exposed by this breach. Most impactfully by the incompetence they demonstrated by not upgrading vaults.

Re: Show HN: I Dedicated 4 Years to Mastering Offline Password Cracking

#27
post #3

Thanks for sharing. This looks interesting. Impressive achievement. This book is currently not really relevant for me, so I just skimmed the samples on Amazon. I found the technical content to be reasonably accurate and interesting although sometimes a little bit verbose (e.g., the section about 'what is a password') or slightly imprecise. In general, I think this book might have benefited from a thorough copyediting…

What did you find slightly imprecise?

It's awkwardly phrased and doesn't really say what it intends to (though, the meaning is obvious after reading it a second or third time).

As for it being imprecise, it doesn't talk about any specific software that has any compatibility issues. It dismisses the topic out of hand.

Post reply on HN