my position is the NSA can crack just about anything if they want to devote their resources to it. 1 billion tries a second? pfft they'll run it in parallel in a warehouse of servers the size of rhode island if they're serious

but in order to do that at all, they have to have a copy, yes? they're not doing that remotely, or even with remote access, because any sane system would notice and halt a spike in authentication requests beyond known peak + some margin. so you're likely pwned for a whole bunch of reasons and the password isn't going to save you

Reply to this note

Please Login to reply.

Discussion

a password is just a little piece of a security system and in these discussions that often gets lost

like the stuff about people extracting data from airgapped systems by using a freaking SATA cable as a radio antenna, the proposed vulnerability is irrelevant because by the time it's accessible, you're already totally compromised

nostr:npub15fkerqqyp9mlh7n8xd6d5k9s27etuvaarvnp2vqed83dw9c603pqs5j9gr talking about systems with access control usually isn't relevant when talking about password cracking. Only really interesting when they have the hash on a local disk.