Brute-Force Attack
- In Turkish
- Kaba Kuvvet Saldırısı
In short
A brute-force attack is an attempt to break into an account or decrypt data by systematically trying huge numbers of possible passwords or keys until one works.
What is a brute-force attack?
A brute-force attack guesses a secret, such as a password, a PIN, an API key, or an encryption key, by trying possibilities one after another until one succeeds. It needs no clever flaw in the software, only time and computing power, which is why the defense is to make the number of possible guesses too large, or the rate of guessing too slow, for the attack to finish. Attacks run either online, against a live sign-in form, or offline, against a stolen database of password hashes on the attacker's own hardware.
Pure brute force tries every combination, which becomes impossible for long random secrets, because each extra character multiplies the work. Real attackers usually take shortcuts: a dictionary attack tries common passwords and words first, credential stuffing replays username and password pairs leaked from other sites, and password spraying tries a few popular passwords against many accounts to stay under lockout limits. Offline attacks use GPUs that can test billions of guesses per second against weak hashes such as unsalted MD5.
Defenses work on both fronts. For online attacks, use rate limiting, growing delays or temporary lockouts after failed attempts, CAPTCHA challenges, and above all two-factor authentication or passkeys, which make a guessed password useless on its own. For offline attacks, store passwords only with slow, salted hashing algorithms such as Argon2id, bcrypt, or scrypt, and encourage long passphrases. It is like a thief trying every key on a giant key ring: the defense is a lock with billions of possible keys and a door that stops opening after a few wrong tries.
A brute-force attack is often confused with a DDoS attack, since both can flood a server with requests. A DDoS attack aims to make a service unavailable, while a brute-force attack aims to get in, and it may even be deliberately slow and spread out to avoid detection.
Key takeaways
- Brute-force attacks try many possible passwords or keys until one works.
- Dictionary attacks, credential stuffing, and password spraying are common shortcuts.
- Online attacks target sign-in forms; offline attacks target stolen password hashes.
- Rate limiting, lockouts, and multi-factor authentication stop most online attacks.
- Slow, salted hashes such as Argon2id or bcrypt make offline guessing far more expensive.
Example
# How long would it take to try every possible password?
GUESSES_PER_SECOND = 10_000_000_000 # a GPU rig against a fast, weak hash
for label, alphabet, length in [
("8 lowercase letters", 26, 8),
("8 mixed characters", 94, 8),
("16 mixed characters", 94, 16),
]:
days = alphabet ** length / GUESSES_PER_SECOND / 86_400
print(f"{label}: {days:.3g} days")
# 8 lowercase letters: 0.000242 days (about 21 seconds)
# 8 mixed characters: 7.06 days
# 16 mixed characters: 4.3e+16 daysReaders ask
How do websites protect against brute-force attacks?
They limit how many sign-in attempts can be made per account and per IP address, add delays or temporary lockouts after failures, and require multi-factor authentication. On the storage side, they hash passwords with slow, salted algorithms so a stolen database is expensive to crack.
What is the difference between brute force and credential stuffing?
Brute force guesses passwords that the attacker does not know yet. Credential stuffing reuses real username and password pairs leaked in other breaches, betting that people reuse the same password on several sites.
How long does it take to brute-force a password?
It depends on the password's length and randomness and on how it is stored. A short password protected by a fast hash can fall in seconds, while a long random passphrase stored with Argon2id or bcrypt would take far longer than a human lifetime.
See also
- Rate LimitingBackend & APIs, p. 37Rate limiting is a technique that caps how many requests a client can make to a server or API within a time window, protecting it from abuse and overload.
- HashingSecurity, p. 14Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
- SaltingSecurity, p. 34Salting is the practice of adding a unique random value to each password before hashing it, so identical passwords produce different hashes and resist cracking.
- Two-Factor AuthenticationSecurity, p. 46Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.
- PasskeySecurity, p. 25A passkey is a passwordless sign-in credential based on public-key cryptography, unlocked with a fingerprint, face scan, or device PIN, that resists phishing.
- DDoSSecurity, p. 10A DDoS attack is an attempt to make a website or online service unavailable by flooding it with traffic from many compromised devices at the same time.
Spotted a mistake or something missing on this page?Suggest an edit