60% of MD5 Password Hashes Crackable in Under an Hour
In honor of World Password Day, Kaspersky researchers released findings indicating that 60% of MD5-hashed passwords can be cracked in under an hour using a single Nvidia RTX 5090 graphics card. Furthermore, 48% of these hashes were compromised in less than a minute. The study, which analyzed over 200 million exposed passwords, attributes this vulnerability to the predictability of user-created passwords and the increasing power of modern hardware. Compared to a similar study conducted in 2024, passwords have become slightly easier to crack in 2026, marking a negative trend in digital security. Experts emphasize that fast hashing algorithms like MD5 are no longer sufficient for protecting user data in the event of a breach. Steven Furnell, a cybersecurity professor at the University of Nottingham, argues that the responsibility lies with service providers rather than users. He urges companies to modernize their login systems and enforce stronger security protections, as users often lack control over the security measures implemented by the platforms they use.
Wire timeline
60% of MD5 Password Hashes Crackable in Under an Hour
In honor of World Password Day, Kaspersky researchers released findings indicating that 60% of MD5-hashed passwords can be cracked in under an hour using a single Nvidia RTX 5090 graphics card. Furthermore, 48% of these hashes were compromised in less than a minute. The study, which analyzed over 200 million exposed passwords, attributes this vulnerability to the predictability of user-created passwords and the increasing power of modern hardware. Compared to a similar study conducted in 2024, passwords have become slightly easier to crack in 2026, marking a negative trend in digital security. Experts emphasize that fast hashing algorithms like MD5 are no longer sufficient for protecting user data in the event of a breach. Steven Furnell, a cybersecurity professor at the University of Nottingham, argues that the responsibility lies with service providers rather than users. He urges companies to modernize their login systems and enforce stronger security protections, as users often lack control over the security measures implemented by the platforms they use.
Slashdot