Nvidia RTX 4090 GPU is alarmingly good at cracking passwords

An Nvidia RTX 4090
(Image credit: Future)

Nvidia’s RTX 4090 graphics card is a bit of a dab hand when it comes to the power and brute force needed to crack passwords, it would seem.

As Tom’s Hardware reports, this comes from a security researcher, Sam Croley, who tweeted about the RTX 4090’s muscle for this task, as gauged by benchmarks run with HashCat (a password cracking tool).

It seems the new Lovelace flagship has an “insane” uplift in cracking performance of over two times compared to the RTX 3090 for “nearly every algorithm”. The new GPU was particularly adept at brute force attacks, combinator attacks, dictionary attacks, mask attacks, and rule-based attacks.

As Tom’s observes, an estimate is provided that a system built specifically for cracking, using eight RTX 4090 graphics cards (yes, a pricey endeavor) could uncover a password of eight characters in length – the most common amount – in less than an hour (48 minutes).

If you’re talking about insecure passwords – you know the sort, ‘password’, ‘123456’ or slightly more complicated but generally simple efforts – then they can be cracked in the blink of an eye, more or less.


Analysis: Password fears as more powerful cracking tech becomes more accessible

All this sounds pretty worrying, of course, but it doesn’t mean your password defenses will crumble tomorrow (unless you are using simplistic passwords, or reusing passwords across sites, or any of those other bad security practices which, to be fair, don’t require an RTX 4090 in the wrong hands to get you in hot water).

What this does serve is a reminder of how in-reach this kind of computing power now is, with a somewhat well-off gamer or PC enthusiast being able to grab an RTX 4090, and possibly misuse it along these lines.

How about really secure passwords? Or indeed those concocted by a password manager in all their seriously complex glory? Croley addresses a query in that Twitter thread where a user asks how long it’d take to fell a 15-character NTLM (Microsoft’s New Technology LAN Manager) password.

Croley replies: “If it’s randomly generated with something like a password manager, too long. There are 95 characters in the common ‘full character set’, and 95^15 is too large of a keyspace for pretty much anyone to attack. Doesn’t really matter how many 4090s or who they are, it’s still too big.”

So is this an argument for getting yourself a password manager, then? Perhaps, and it’s certainly food for thought. If you’re mulling over grabbing such an app, then hop on over to our roundup of the best password managers, where we pick out the top performers in this field. And if you don’t use an app to keep your passwords watertight, make sure you aren’t taking silly shortcuts like using obvious passwords, or jotting them down in a pad somewhere, or similar…

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Read more
A masculine hand holding an RTX 5090
$2000 Nvidia Geforce RTX 5090 gets tested on creative software and AI and obliterates absolutely everything in its path
Moody shot of an Nvidia GPU
Nvidia RTX 5090 FE rumor claims high-end GPU gets loud - but other reports tell a very different story
A photo of the Bizontech ZX5500 on a black background
Absurdly powerful PC with 7 liquid-cooled Nvidia RTX 5090 GPUs has just gone on sale — and it is in stock
An RTX 5090 graphics card resting against its retail box with a closeup of the RTX 5090 branding
Nvidia's RTX 5090 has already been pushed beyond its limit - ROG Astral model overclock reaches 3.45GHz and 35 Gbps VRAM
The RTX 5090 imprint on the Nvidia GeForce RTX 5090
Sorry, AMD, Nvidia's price tags for its RTX 5000 GPUs could win me over
An Nvidia GeForce RTX 5000 GPU on a green patterned background.
A possible Nvidia RTX 5090 prototype shows what might have been – an absolute monster with nearly 25K CUDA cores and an 800W TDP
Latest in Security
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Biometrics add another layer of security to passwordless authentication
Data leak
Hacked Tata Technologies data leaked by ransomware gang
A close-up photo of an iPhone, with the App Store icon prominent in the center of the image.
Thousands of iOS apps found to expose user data and leak Stripe keys
Latest in News
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A smartphone on a sofa showing the WhatsApp, Telegram and Signal apps
Forget AI – WhatsApp is planning a simple messages feature that could be its most useful upgrade in years
NordicTrack Ultra 1
The new NordicTrack Ultra 1 treadmill looks like it was designed by an architect and costs $15,000
An Nvidia GeForce RTX 5070
Nvidia RTX 5080 stock is so barren that retailers are holding competitions where you can "win" the right to buy one for MSRP
Assassin's Creed Shadows
Ubisoft shareholder accuses publisher of 'misleading investors', plans protest outside Paris HQ
Google Gemini AI logo on a smartphone with Google background
I made an AI version of Bilbo Baggins using Goggle Gemini for free, and shared a pipe with him outside Bag End – here’s what you can now do with Gems