5 ms·
This is an odd conclusion to come to. Are there a lot of users of True/Veracrypt that don't understand this? I guess I just don't see my grandparents using eith
by m82labs 11y ago
This is an odd conclusion to come to. Are there a lot of users of True/Veracrypt that don't understand this? I guess I just don't see my grandparents using either of these packages, and I can't imagine a lot of "normal" users "trying out" a new encryption program.
- tired_man 11y agoJust because a person is older than you doesn't mean they're either stupid or completely non-technical. Plenty of older people started using computer in the middle of the sixties. So what if we started with card punch machines, tape readers, and mainframes? Just exactly what do you mean by "normal?" How much computer exposure does it take before one loses that quality and becomes, well, "you?" There are lots of grandparents coding away in cubes across the world or tinkering with their prized home-brew desktop rig. Take a reality pill, kiddo. If anything, there are fewer younger people who will tinker with crypto because the vast majority of them think they're invincible, indestructible, and immortal, when they're really just inexperienced and gullible.
- icebraining 11y agoI understand that there's a prejudice against older people regarding technical ability, but the parent poster didn't actually say anything regarding old people in general, just about his/her grandparents specifically.
- tired_man 11y agoGrandparents _are_ the prototypical older generation. Read areound. That's become the common usage ;-)
- icebraining 11y agoSo how are we supposed to refer to our actual grandparents, without people assuming we're making a generalization?
- kijin 11y ago10 seconds is ridiculous, especially if you know what you're doing and use strong passphrases. The passphrase to one of my TrueCrypt volumes is around 30 characters long. It's not completely random, so let's say it only has 2 bits of entropy per character. That's 60 bits total. A brute-force attack would take an average of 2^59 guesses before it succeeds. At 10 seconds per guess, we're looking at approximately 180 billion years to crack my passphrase. Even if you devoted a million computers to the job (as an extremely well-funded adversary might do), it would still take 180,000 years. If you weakened the PBKDF to take 1 second instead, it would take 18,000 years to crack my relatively weak passphrase using a million computers. That's still long enough that I don't care at all. Moreover, if I were really paranoid, I can easily bring it back to the 180,000-year mark (or more) by adding a few more characters to my passphrase, which would only take another second to type. So why wait 10 seconds?
- monort 11y agoYou can bruteforce much faster on GPU. E.g. 20*10^9 ripe160 hashes per second on 8x AMD R9 290X (price is around $3000): https://hashcat.net/oclhashcat/ https://hashcat.net/oclhashcat/ 60 bits are not secure against attacker with medium budget.
- luck87 11y agoSome years before oclHashCat support, I buil a gpu cracker for truecrypt volume TrueCrack (https://code.google.com/p/truecrack/ https://code.google.com/p/truecrack/) . To be honest oclHashCat has better performance. Now the board of the oclHashCat tests ( AMD R9 290X ) costs about 300 euro (not $3000).
- monort 11y agoThey used 8 cards for that test.
- kijin 11y agoThen we can use GPUs to speed up VeraCrypt's PBKDF, too. The point is that there's no need for a PBKDF that takes 10 seconds on modern hardware. Sure, that 60-bit passphrase is weak. But it takes a trivial amount of effort to increase the entropy of a passphrase. Let's say I increased it to 80 bits. In terms of brute-force resistance, that's equivalent to increasing the PBKDF's iteration count 1 million times.