Mandiant's explanation that the recent hack of its Twitter account was the result of a "brute force password attack" illustrates precisely why the frequent misuse of this term is problematic.

Once upon a time, brute force was a very particular form of password cracking technique. Specifically, it meant an attacker methodically tried every possible password combination until, finally, arriving at the correct one. It stood in contract to a "dictionary" password attack, in which an attacker used a finite list of likely strings in hopes one was correct.

Now that brute force and dictionary have become synonymous, we're left to guess (although I'm going to guess in this case it was the latter).

#wordpedant

infosec.exchange/@mandiant@bir

Follow

@dangoodin Yeah, when I read that I thought "really?" It seems like a true brute force attack wouldn't be possible on most online services just because you couldn't try enough combinations fast enough (unless they allow many concurrent attempts to login to the same account).

Sign in to participate in the conversation
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.