CYBER WELFARE

Protect your Digital Privacy

Brute Force Attacks: How They Work and What Stops Them

Additional resource for the lesson “Brute Force Attacks: How They Work and What Stops Them” — Online Security course

A brute force attack is a machine trying passwords one after another until one works. There is nothing clever about it — which is exactly why it succeeds so often against short passwords, and fails so completely against long ones. This resource explains where the line sits.

A. Why this matters

A brute force attack works by trying an enormous number of passwords automatically until one of them opens the account. There is no insight involved and no target selection: it is a machine working through possibilities.

That makes the outcome a question of arithmetic rather than luck. If a password is short, simple or reused, the number of attempts needed collapses to something a computer gets through quickly. If it is long and unpredictable, the same attack would take longer than anyone is willing to wait.

The key idea: you do not have to outwit the attack. You only have to make it take too long to be worth running.

B. Key concepts

Six ideas, each with what it changes for your own accounts.

Brute force attack

Automated attempts at many possible password combinations until the right one is found. Simple, and effective whenever the password is weak.

Why it matters to you: It explains why a password that feels ‘good enough’ can fail: the attack does not care how clever it looks, only how many guesses it takes.

The space of combinations

The total number of passwords an attacker would have to work through. It grows with the length of the password and the variety of characters in it — and it grows very fast.

Why it matters to you: Adding characters does not make the attack a little harder. It multiplies the work required, which is why length is the lever that matters.

Weak and predictable passwords

Dictionary words, names, dates and old favourites like Password123. These sit in the lists attackers try first, before any real brute forcing begins.

Why it matters to you: A predictable password is not broken by brute force at all. It is simply looked up — which takes no time worth measuring.

Strong passwords and passphrases

Long credentials — ideally 16 characters or more — mixing upper and lower case, numbers and symbols, or several unrelated words strung together.

Why it matters to you: Both routes get you to the same place. The passphrase route is the one you can do from memory when you have to.

Password manager

A tool that generates and stores a unique, long password for every account, so you never have to invent one.

Why it matters to you: It removes the reason people reuse passwords in the first place, and the passwords it produces are the kind brute force cannot reach.

Defences on the service side

Limits on login attempts, temporary lockouts, alerts on failed sign-ins, CAPTCHA and multi-factor authentication.

Why it matters to you: These are not under your control, but where a service offers them — especially attempt alerts and MFA — turning them on is worth the two minutes.

C. A practical example: two passwords, two outcomes

Consider two people protecting the same kind of account.

The first

Their password is a single ordinary word:

almondmilk

It never reaches the brute force stage. It is a dictionary word, so it appears in the lists tried first, and the account opens almost immediately.

The second

Their password came out of a password manager:

A1m0nd!M1lk_Harbour7

Twenty characters, mixed types, connected to nothing about them. The space of combinations an attacker would have to work through is large enough that a complete search stops being a realistic plan.

And if the account also has multi-factor authentication switched on, even a password that somehow leaked would not be enough on its own.

The difference between the two is not intelligence or technical skill. It is ten characters and a tool that generates them for you.

D. Try it yourself: how long would yours last?

Five minutes. Do not type any of your real passwords into anything during this exercise — including websites that offer to rate them.

Step 1 — Judge three examples

  • chocolate
  • MySpace1
  • Green!Fog_Tower1979
  • For each one ask: is it short or long? Letters only, or a mix? Is it a word someone could find in a dictionary?

Step 2 — Rewrite the weakest one

  • Turn chocolate into something that would survive: four unconnected words, plus a number and a symbol.
  • Notice how little effort it took to move it out of reach.

Step 3 — Apply it once, for real

  • Think of one account where your password is closer to the first example than the third.
  • Change that one. Not all of them — one.

Do not test your real passwords on websites that estimate how long they would take to crack. Whatever you type is a password you have now shared.

The point of the exercise is to make the gap tangible. Once you have seen how short the distance is between a password that fails instantly and one that holds, the change stops feeling like a chore.

E. Videos, articles and further resources

Independent and institutional sources in English.

NIST — Digital Identity Guidelines, SP 800-63B (Revision 4)
The August 2025 standard behind the shift from complexity to length. Technical, but this is where the 15-character recommendation comes from.
https://pages.nist.gov/800-63-4/sp800-63b.html

CISA — Use strong passwords
Plain-language guidance on password length and on using a password manager.
https://www.cisa.gov/secure-our-world/use-strong-passwords

NCSC (UK) — Three random words, or #thinkrandom
Why three random words beat conventional complexity rules — and why that also makes them harder to brute force.
https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0

NCSC (UK) — Password managers: how they help you secure passwords
A sober answer to the question most people ask first: is it safe to keep all my passwords in one place?
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/password-managers

EFF — Creating strong passwords
A clear method for building a passphrase you can actually remember, including the dice-based approach.
https://ssd.eff.org/module/creating-strong-passwords

NCSC (UK) — Top tips for staying secure online
Six short pieces of advice from the UK’s national cyber security authority. A good starting point if you want the essentials without the jargon.
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online

Links checked in August 2026.

F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior

This lesson works mainly on the Awareness pillar at level FL2: understanding the mechanism is what makes the recommended behaviour feel reasonable.

Skills

  • Judging whether a password is within reach of automated guessing.
  • Building long, unique passwords and passphrases (R3, MS1).
  • Using a password manager properly rather than occasionally (R2, MS2).

For professionals and organizations

  • Recognising that attempt limits and login alerts are the service-side half of the same problem.

Awareness

  • Understanding that short words — even unusual ones — are in the lists tried first.
  • Seeing that reuse turns one exposed password into a way into several accounts at once.

For future instructors and ambassadors

  • Being able to explain the arithmetic without a lecture: length multiplies the work, complexity only adds to it.

Secure Behavior

  • Moving critical accounts to long, unique credentials (R1, R3, MS1).
  • Turning on multi-factor authentication where it exists (R4, MS17).
  • Letting a password manager do the generating (R2, MS2).

For organizations

  • Enabling attempt limits and failed-login alerts on the services you control (R8).

G. Questions to sit with

  1. How many of your passwords today could be reached in minutes because they are short, predictable or reused?
  2. Do you have a critical account — primary email, online banking, a work portal — still protected by one of them?
  3. If one of your passwords were exposed, how many other accounts would open with it?
  4. Which account are you willing to put out of reach today?

H. What to do now

The recommendations (R) and security measures (MS) from the Cyber Welfare database that apply to defending against automated guessing.

Credentials

  • R1 — Do not use the same, or nearly the same, password across your accounts.
  • R2 — Use a reliable password manager, protected by a strong and unique master password.
  • R3 — Make your passwords at least 16 characters, combining numbers, upper and lower case letters and symbols.
  • R4 — Turn on multi-factor authentication, with an authenticator app or a hardware key.
  • MS1 — Let the manager’s generator create your passwords rather than inventing them.
  • MS2 — Let it fill them in automatically: fewer errors, and less exposure to fake sign-in pages.

Where the service allows it

  • R8 — Turn on login attempt limits and alerts for failed sign-ins.
  • MS4 — Use a strong alphanumeric passcode on the device where your password manager lives.

Three things, today

  1. Choose one critical account — start with your primary email.
  2. Give it a new long, unique password from a generator (R3, MS1).
  3. Turn on multi-factor authentication for it (R4, MS17).

Those three steps move that account out of reach of automated guessing. The rest can follow at your own pace.

In short

  • Brute force is arithmetic, not insight — and length is the variable that decides the outcome.
  • Predictable passwords never even reach the brute force stage: they are looked up.
  • A password manager produces credentials the attack cannot reach, and removes the reason to reuse.
  • MFA means a leaked password is not enough on its own.

Related resources in this course

The same problem, seen from three other angles:

Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.

If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.

→ Join the Cyber Welfare Program