Brute-Force

Brute-Force Attack

Brute-Force-Angriff

A brute-force attack systematically tries all possible combinations to guess a password or a key — raw computing power instead of finesse. Its prospect of success depends solely on the strength of the secret and the protective measures. Against short or weak passwords it is alarmingly effective.

History & facts. The principle is as old as the password itself: try until it fits. Modern hardware tests enormous quantities of combinations per second, which is why short passwords fall in next to no time. Related variants are the dictionary attack (targeted trying of likely terms) and credential stuffing (reusing credentials leaked elsewhere). Poorly protected password hashes worsen the problem because attackers can guess offline and en masse. Outlook & recommendation. The countermeasures are known and effective: long, unique passwords, a second-factor protection (2FA/MFA), locking or delaying after failed attempts and the secure, slow hashing of stored passwords with salt. On the detection side, clustered failed logins are a clear signal that central log analysis reliably reveals. Where MFA takes hold consistently, brute force loses most of its danger.
Brute-Force — Brute-Force Attack