Why does Windows take longer to verify a wrong password? Developer explains 1

Why does Windows take longer to verify a wrong password? Developer explains

Who has never typed a password wrong and waited until you realized it wasn’t accepted? At some point in our lives, we all face this situation.

And it’s not just a coincidence that invalid passwords take longer to be rejected than valid ones.

In a new blog post from WindowsRaymond Chen, a developer at the company for over 30 years, provided some explanations regarding this curious phenomenon.

Why do wrong passwords take longer to identify?

Why does Windows take longer to verify a wrong password? Developer explains 2

Have you noticed? Time for checking correct and incorrect passwords in Windows is different – ​​Image: Reproduction

According to Chen, there are two main reasons that justify this delay in rejecting invalid passwords: a security issue and a longer validation process.

The first reason is related to the security adopted to reduce the effectiveness of so-called dictionary attacks.

This type of attack aims to discover passwords through a series of attempts involving thousands, sometimes millions, of possible combinations.

If the rejection of passwords invalid passwords were as fast as accepting valid passwords, the time needed to make these countless attempts would be significantly reduced.

“For example, suppose you have a dictionary of 75,000 words and passwords are accepted or rejected in 100 milliseconds. It would take just over three hours to try all the passwords. Now, if rejecting invalid passwords took 5 seconds longer, the time required to perform a full password dictionary search would increase to more than four days,” explains Chen.

Validation of passwords not found in the cache

The second reason for the delay in rejecting invalid passwords has to do with the validation process adopted by computers.

This process consists of two steps:

  1. If the password entered is in the computer’s cache (a type of temporary memory that stores frequently used data), it will be validated immediately;
  2. If it is not in the cache, the computer must contact the domain controller to validate the password. This procedure is adopted because the computer’s cache itself may be out of date.

If a user recently changed their password on another machine, their computer’s cache may still be storing the old password.

If the computer simply rejected the password that was not in the cache, the user would not be able to access their account through a computer that has the old password in cache.

He would have to wait as long as necessary for the old password to be replaced in the cache with the new password provided by the domain controller.

So the next time you enter a wrong password, remember that the delay in rejection is not a simple whim of the systembut a security measure adopted to protect your information against intrusion attempts.

Support our work ❤️

If you enjoyed this article, consider leaving a tip to help us keep publishing great content.

Secure payment on PayPal
Moyens I/O Staff is a team of expert writers passionate about technology, innovation, and digital trends. With strong expertise in AI, mobile apps, gaming, and digital culture, we produce accurate, verified, and valuable content. Our mission: to provide reliable and clear information to help you navigate the ever-evolving digital world. Discover what our readers say on Trustpilot.