Within an hour, more than 60 % of passwords are cracked from MD5 hashes using a single GeForce RTX 5090
How Quickly Can MD5 Passwords Be Cracked: Findings from the Kaspersky Lab Study
In 2024, researchers at Kaspersky Lab analyzed over 231 million stolen passwords collected from dark‑net leaks. After hashing them with MD5, they discovered that:
- 60 % of passwords can be cracked in less than an hour.
- 48 % can already be cracked within a minute.
All this requires just one Nvidia GeForce RTX 5090 graphics card.
Why It’s So Fast
1. Low Complexity of MD5
The MD5 algorithm has long been considered obsolete; its hashes are easy to brute‑force with modern GPUs.
2. Optimization for Specific Passwords
Analysis of over 200 million passwords revealed patterns (common templates, simple words, etc.) that reduce search time.
3. Growth in GPU Power
Since the first study in 2024, GPU performance has surged while the passwords themselves have not become harder.
What This Means for Users
- Passwords protected only by MD5 hashes are no longer reliable. If an attacker obtains them from a breach, they can quickly gain account access.
- Professional hackers can rent GPU power from cloud providers, so even inexpensive cards pose a threat.
Why The Problem Is More Than Just “Switching to SHA”
Experts at The Register point out several factors:
1. Lack of Awareness
Users and organizations are largely unaware of the risks posed by weak passwords.
2. Weak Password Requirements
Many platforms maintain lenient rules, not requiring length, complexity, or regular updates.
3. Insufficient Additional Protections
- Two‑factor authentication (2FA) is still seen as “adequate”; biometrics are considered the most reliable second factor.
- Systems are not always protected against lateral movement by an attacker after initial compromise.
What Can Be Done
- Switch to stronger hashes (bcrypt, Argon2) and use salts.
- Implement strict password policies: at least 12 characters, a mix of letters, numbers, and special symbols.
- Enforce mandatory two‑factor authentication, preferably with biometrics or hardware tokens.
- Conduct regular security audits and staff training.
Thus, even simple MD5 passwords already pose a serious threat. Comprehensive protection measures are the only way to reduce cyberattack risk in today’s environment.
Comments (0)
Share your thoughts — please be polite and stay on topic.
Log in to comment