Brute-force attack
An attack that automatically tries a large number of possibilities in turn until it finds the right password or key.
- 01
Why it matters
Short, predictable passwords can be found within minutes; sign-in pages, remote desktop and e-mail accounts exposed to the internet face such attempts constantly. Attempt limits, temporary lockouts, multi-factor authentication and long passwords make the attack useless in practice.
- 02
Example
A site's admin sign-in page has no attempt limit. The logs show thousands of passwords tried per hour from a single address; once a limit and multi-factor authentication are added, the attempts lead nowhere.
- 03
Common mistake
Considering complex but short passwords safe. Length matters more than complexity; a long passphrase of several words and a password manager are safer.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.