Skip to main content

Brute-Force Attack

Updated 3 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/brute-force-attack

In short

A brute-force attack is an attempt to break into an account or decrypt data by systematically trying huge numbers of possible passwords or keys until one works.

What is a brute-force attack?

A brute-force attack guesses a secret, such as a password, a PIN, an API key, or an encryption key, by trying possibilities one after another until one succeeds. It needs no clever flaw in the software, only time and computing power, which is why the defense is to make the number of possible guesses too large, or the rate of guessing too slow, for the attack to finish. Attacks run either online, against a live sign-in form, or offline, against a stolen database of password hashes on the attacker's own hardware.

Pure brute force tries every combination, which becomes impossible for long random secrets, because each extra character multiplies the work. Real attackers usually take shortcuts: a dictionary attack tries common passwords and words first, credential stuffing replays username and password pairs leaked from other sites, and password spraying tries a few popular passwords against many accounts to stay under lockout limits. Offline attacks use GPUs that can test billions of guesses per second against weak hashes such as unsalted MD5.

Defenses work on both fronts. For online attacks, use rate limiting, growing delays or temporary lockouts after failed attempts, CAPTCHA challenges, and above all two-factor authentication or passkeys, which make a guessed password useless on its own. For offline attacks, store passwords only with slow, salted hashing algorithms such as Argon2id, bcrypt, or scrypt, and encourage long passphrases. It is like a thief trying every key on a giant key ring: the defense is a lock with billions of possible keys and a door that stops opening after a few wrong tries.

A brute-force attack is often confused with a DDoS attack, since both can flood a server with requests. A DDoS attack aims to make a service unavailable, while a brute-force attack aims to get in, and it may even be deliberately slow and spread out to avoid detection.

Key takeaways

  • Brute-force attacks try many possible passwords or keys until one works.
  • Dictionary attacks, credential stuffing, and password spraying are common shortcuts.
  • Online attacks target sign-in forms; offline attacks target stolen password hashes.
  • Rate limiting, lockouts, and multi-factor authentication stop most online attacks.
  • Slow, salted hashes such as Argon2id or bcrypt make offline guessing far more expensive.

Example

Why password length matterspython
# How long would it take to try every possible password?
GUESSES_PER_SECOND = 10_000_000_000  # a GPU rig against a fast, weak hash

for label, alphabet, length in [
    ("8 lowercase letters", 26, 8),
    ("8 mixed characters", 94, 8),
    ("16 mixed characters", 94, 16),
]:
    days = alphabet ** length / GUESSES_PER_SECOND / 86_400
    print(f"{label}: {days:.3g} days")

# 8 lowercase letters: 0.000242 days (about 21 seconds)
# 8 mixed characters: 7.06 days
# 16 mixed characters: 4.3e+16 days

Readers ask

How do websites protect against brute-force attacks?

They limit how many sign-in attempts can be made per account and per IP address, add delays or temporary lockouts after failures, and require multi-factor authentication. On the storage side, they hash passwords with slow, salted algorithms so a stolen database is expensive to crack.

What is the difference between brute force and credential stuffing?

Brute force guesses passwords that the attacker does not know yet. Credential stuffing reuses real username and password pairs leaked in other breaches, betting that people reuse the same password on several sites.

How long does it take to brute-force a password?

It depends on the password's length and randomness and on how it is stored. A short password protected by a fast hash can fall in seconds, while a long random passphrase stored with Argon2id or bcrypt would take far longer than a human lifetime.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings