Last year we built a password cracking rig for our team, and did some fun demos at BlackHat, SecTor, and several events and conferences. Having access to hardware, we have also had some time to do research. Do people still use bad passwords? Of course. But now we have some evidence behind it, and want to present our research, and things that we have found in the last year. Including how we are reversing NTLMv1 challenge hashes to NTLM hashes in under 12 hours.