Imagine it as physical safe secured by combination lock. (In simplest way it actually is)
You can try every possible combination, but that takes time…
Easiest way is to get the right combination elsewhere…
Bad lock will have its password written on it (stored as plaintext)
You can try to make similar looking safe and give it to user. Once they enter the correct combination, you have it too.
You can exploit bug in the lock or the safe itself, to get inside.
You can wait till the user opens the safe and steal the data right from their desk
Latest Answers