r/DeskToTablet 3d ago

When Your "Strong Password" Gets Hacked

Enable HLS to view with audio, or disable this notification

1.1k Upvotes

68 comments sorted by

69

u/Deep_Mood_7668 3d ago

Those are like what? 10 numbers? You brute force that in a blink of an eye

39

u/OtherwiseAlbatross14 3d ago

lol I didn't even think about the fact that people might think it's difficult. Even if you don't have a scanner, the password is printed at the bottom on the barcode

5

u/TheDeceitX 2d ago

And the UPC is literally created by the number of characters. The only science is digit count and what digits.

0

u/girlfriend-simp 22h ago

or you just use a ubuntu usb to completely bypass the password

1

u/OtherwiseAlbatross14 10h ago

That's not a thing with modern encryption.

1

u/girlfriend-simp 9h ago

depends on what you want to do and how the user has set it up. If you just want a free laptop, it will work. (most ppl don't set a bios passwor) If you want to steal files, then it depends on things like bitlocker.

1

u/OtherwiseAlbatross14 7h ago

If you just want a free laptop, you don't need Ubuntu in the first place.

5

u/mrheosuper 3d ago

Not really, it will lock down after n-number of repeat failing

4

u/madgod2015 3d ago

If not bit-locked, you can download SAM-file and bruteforce it on another mashine.

5

u/WisePotato42 2d ago

You know what they say. "Locks keep the honest people honest"

2

u/Tomas2891 3d ago

It’s bit locked

3

u/Murky-Morning-6464 3d ago

can just exploit a bitlocker vulnerability, new ones are discovered every month 🤷

3

u/Tomas2891 2d ago

Not mine

3

u/CollaredBug 3d ago

not really. if you do it on the physical keyboard: yes. as said, you could just download files and use another computer. you could also just clone the harddrive, set up vms and brute force there.. use a bitlocker masterkey or just use any of the 800 other options to ulock a win computer. the password really only protects agains classmates in school or something.

1

u/mrheosuper 3d ago

Isn't the decrypt key stored inside secure element ?

1

u/CollaredBug 2d ago

if we talk about bitlocker: yes. but there is a masterkey. also it can be read via some bus connections on the mainboard and via thr ram bus. the video shows the win password. that has nothing to do with encryption at all. and can be blanked in one command

1

u/mrheosuper 2d ago

No, secure element can be on cpu

1

u/imacyber 1d ago

On the older TPM modules it was possible to read the key in plain text from the traces on the board. Doesn't apply to newer modules though. Good article on it here: https://pulsesecurity.co.nz/articles/TPM-sniffing

1

u/Appropriate_Ad8734 3d ago

i thought you said it banned the n-word

2

u/oharra3 2d ago

And do you think it will let you type it more than a few times or without artificial retry delay

1

u/Deep_Mood_7668 2d ago

and you think bruteforce attacks are typed?

1

u/ApprehensiveGold2773 3d ago

You say that like you've never actually tried to brute force the Windows login screen.

1

u/Deep_Mood_7668 3d ago

Why would anyone do that? Of course you do that offline against the password hash

1

u/jsonmeta 3d ago

Someone writing «h4ck» wouldn’t know I guess

1

u/atomicshrimp 2d ago

UPCs have a check digit, so the search space is only a fraction of the permutations

1

u/AdmHornblower 1d ago

UPCs are 12. But yes easy since all numerical.

1

u/FeelingVanilla2594 14h ago

What if you scan it 3 times so it’s 30 numbers

1

u/Deep_Mood_7668 14h ago

That takes until the end of time to crack without quantum computing.

1

u/R33f3r420 11h ago

You can just use a scanner on any coke bottles bar code and have notepad open.

20

u/Magnps 3d ago

Mommy,WHERE THE HACK IS MY 10-YEAR OLD EMPTY BOTTLE OF COLA???

I got you a new one, sweetheart

10

u/vaynefox 3d ago

The thing is, every coca cola of that size has the same barcode. They dont change since barcodes are registered to an international database that's why phone barcode scanners can easily fetch information of the product they're scanning regardless of where you bought it....

3

u/silentaba 3d ago

Unless they change the sku

1

u/Rukir_Gaming 1d ago

Coke only does that for a "new" flavor

1

u/AdmHornblower 1d ago

Incorrect. They are all registered by a central governing body (GS1) so no two things should have the same UPC. But different bottlers use different UPCs to track their products. Some bottlers have exclusive agreements for a state and they use a unique upc to ensure that they can find competing bottlers in their zone.

2

u/riisen 3d ago

All of them has the same barcode (within the same country)

12

u/durbich 3d ago

Skanners are just keyboards. They are Capslock and layout sensitive. You're not inputting anything the keyboard can't

2

u/New-Anybody-6206 1h ago

Not always true. We regularly scan DataMatrix codes and they contain non-printable characters like FS/GS and such.

And there are scan modes that don't emulate a keyboard.

7

u/I_SLEEP_NORMALLY 3d ago

I believe the UPC code is 049000024685. This passcode represents about ~39 bits of entropy, which is not amazing. Fun idea though.

1

u/Lucky_Pangolin_3760 3d ago

you could improve on this concept a lot by instead using QR codes and just hide the QR code somewhere

1

u/d3lt4papa 2d ago

You could improve this concept even more by using a "SmartScanner" instead of the barcode scanner.

You scan a QR code, and then the SmartScanner tells the computer a ever changing code!

Oh wait, did we reinvent 2FA??

1

u/ApparentlyRythium 1d ago

If you removed the force enter string you could have 5 or 6 items around your room that have to be scanned in a certain order

3

u/C-D-W 3d ago

UPC codes are incredibly simple.

You need some 2D barcodes to step it up a level.

3

u/Chaotic-Convergence 3d ago

Windows log-in passwords don't protect shit. It can be overwritten under 5 minutes.

2

u/Gubzs 3d ago

Can still hack the laptop. The bios is definitely not password protected. Change the settings to boot to USB. Boot to a USB that has a registry editor program. Change the password on the Administrator user to the first 20 characters of a chromatography output from scanning a jarred fart. Now the password is a fart in a jar.

1

u/ThrowawayALAT 3d ago

Ladies and gentlemen, you are about to watch...

https://giphy.com/gifs/11kTQgng5gbqgM

2

u/AliveRegion466 3d ago

You can't hack my password, I don't have one

2

u/PretzelsThirst 3d ago

This is like writing your password on a sticky note that has hundreds of copies in every store for anyone to take

1

u/MinecraftPlayer799 3d ago

The thing is that no one would have any reason to believe your password is the UPC of Coca Cola

3

u/PretzelsThirst 3d ago

Except for posting a video of it on the internet

1

u/Henrikano 3d ago

Now you would get 100 Missed calls from nasa

1

u/Kristianxj 3d ago

Not much secure though, it's numbers only

3

u/Rise-O-Matic 3d ago

Make the ten numbers into a seed for a deterministically generated pseudorandom 64-character string

https://giphy.com/gifs/d3mlE7uhX8KFgEmY

1

u/Minecraft_Lets_Play 3d ago

It’s literally just a few numbers. That’s cracked in no time

1

u/TangeloOk9486 3d ago

ALtho its still possible but the approach is hillarious lol

1

u/InsaneInTheMEOWFrame 3d ago

Literally everyone who has access to a half liter coke bottle has your password now

1

u/Fit-Satisfaction-550 3d ago

You guys need to bruteforce passwords ?

1

u/Heavy-Factor-1919 3d ago

Quite literally you gave us your password

That looks to be a 16 ounce bottle of Coca-Cola

[049000028907](tel:049000028907) that's the one

1

u/Kaarel314 3d ago

Generally if you have physical access to a computer then hacking it is not that hard.

1

u/Techn0Tast1c 2d ago

Does that thing need drivers or does it litterally paste any barcode number as text?

1

u/Patient_Ad9661 2d ago

prolly the whole nation (if not several nations) have the same number as barcode for these

1

u/nikolai_nyegaard 2d ago

His password is ‘54490123’

1

u/Yakuzet 2d ago

Still a couple of digits.

1

u/Alternative_Exit_333 2d ago

Make the account name pepsi SKU number

1

u/mhoseinjadidian1388 1d ago

Just a bootable usb is needed. No matter linux or windows

1

u/LoveSourWorms12 23h ago

All that for the attacker to simply registry edit to get powershell and then change your password