Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Good news for people who followed best practices. "I don't have to outrun the bear; I just have to outrun you."


This bear has the ability to spin up an AWS cluster of bears, unfortunately.


They're still subject to economic considerations (assuming a non-state actor). If the expected value on a cracked account is less than the expected cost to crack it, a rational actor won't bother. That they may use cracked AWS accounts, or botnets, to perform this cracking does not change these economic considerations.


AWS is probably the most expensive way to do this.

Either rent some machines from an ex-crypto miner, since AES can be decyphered on GPUs or get some old extremely cheap boxes from the hetzner auction.


People who are trying to crack these passwords are also likely to be using compromised AWS accounts.


There isn't just one bear.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: