RTX 4090 Sets New Records in Password Cracking Benchmarks
The new Nvidia GeForce RTX 4090 is setting the standard for high-end gaming, but that’s not all it can do. The card’s raw processing ability also makes it the most powerful password cracker in the world. Early benchmarks show the 4090 crushed the cracking capabilities of the previous market leader, Nvidia’s RTX 3090. With enough GPUs cranking away, it’s possible to decrypt shorter passwords in less than an hour.
Password researcher Sam Croley (@Chick3nman512 on Twitter) recently posted the first Hashcat benchmarks for the RTX 4090. According to Croley, the improvement is substantial with a roughly 2x uplift in almost every cracking algorithm versus the 3090. Hashcat bills itself as an advanced password recovery tool, allowing the forgetful to (maybe) recover a lost login. However, it can be used just as easily to crack someone else’s password.
The 4090 was tested against protocols like Microsoft’s New Technology LAN Manager (NTLM) authentication and Bcrypt, both of which create “hashes” of plain text passwords to make them unreadable in the event someone who isn’t you should gain access to them. To unscramble the passwords, Hashcat uses several different algorithms to search for the real password, including brute force attacks, mask attacks, and rule-based attacks.
First @hashcat benchmarks on the new @nvidia RTX 4090! Coming in at an insane >2x uplift over the 3090 for nearly every algorithm. Easily capable of setting records: 300GH/s NTLM and 200kh/s bcrypt w/ OC! Thanks to blazer for the run. Full benchmarks here: https://t.co/Bftucib7P9 pic.twitter.com/KHV5yCUkV4
— Chick3nman 🐔 (@Chick3nman512) October 14, 2022
The benchmarks show that a rack of eight GeForce RTX 4090 cards could unlock an 8-character password in just 48 minutes. That’s 2.5 times faster than the 3090. In some cases, when passwords use dictionary words or have identifiable patterns, the cracking time can drop to mere milliseconds. This was all done with commercially available hardware and software.
This is a troubling trend and probably something security researchers will have to plan for in the future. However, it’s not a security emergency just yet. For one, you’ll need multiple 4090 cards to crack passwords at a fast enough rate to be useful. Second, the passwords tested in Hashcat are just eight characters. Many sites and services require more than that, and each new character adds to the complexity of the problem.
Anyone who wants to use Nvidia’s latest GPUs to crack passwords will have to save up some serious cash and get in line. Currently, the cards are in extremely short supply, and the starting price is $1,600. Versions of the 4090 from manufacturers like Asus and Gigabyte can climb even higher.
Continue reading
Benchmark Results Show Apple M1 Beating Every Intel-Powered MacBook Pro
Apple's new M1 SoC can beat every single Intel system it sells, at least in one early benchmark result. We dig into the numbers and the likely competitive situation.
Leaked Benchmarks Paint Conflicting Picture of Intel’s Rocket Lake
Rumors about Rocket Lake have pointed in two opposite directions recently, but the more competitive figures are more likely to be true.
Cyberpunk 2077 Benchmarks Show Even the Fastest GPU in the World Can’t Play at 4K
It was probably impossible for Cyberpunk 2077 to live up to the hype after eight years in development, but the performance issues aren't helping.
Apple’s M1 Crushes Windows on ARM in 64-bit Benchmarks
Now that Windows on ARM can emulate 64-bit x86 apps, how do these systems compare against Apple's M1? Not well, it turns out.