3 ms·
Details, in case it's helpful/interesting to anyone: https://keybase.io/docs/api/1.0/call/login https://keybase.io/docs/api/1.0/call/login . Also of note, the
by malgorithms 11y ago
Details, in case it's helpful/interesting to anyone: https://keybase.io/docs/api/1.0/call/login https://keybase.io/docs/api/1.0/call/login . Also of note, the hashing is done client side, not server-side.
- hinkley 11y agoDoesn't that mean the hash is the password, not the password? If I steal the password file what keeps me from just logging in as everybody?
- darkr 11y agoCan't vouch that this is the case with keybase, but where I've seen this done before, the hash is calculated in combination with some kind of time-based shared secret at both at the server and the client and then compared, with the theory being it would protect against the TLS connection is MITM'd; all the attacker would get is the hash, which is then useless as the time element isn't known. IMHO, MITM would be better defended against using HSTS, certificate pinning, and perhaps DNSSEC.
- nitrogen 11y agoIt seems like it would be better to just use SRP (https://en.wikipedia.org/wiki/Secure_Remote_Password_protocol https://en.wikipedia.org/wiki/Secure_Remote_Password_protoco...). SRP defends against replay attacks, and could potentially use a modified bcrypt or scrypt for H() to limit brute force attempts.
- EvanDotPro 11y agoTechnically yes, but I would imagine they'd subsequently hash the hash on the server side as well. I assume the extra client-side hashing is done to keep the plaintext passwords out of the application memory, not protect it in transit. To clarify, this is just an assumption. I have not read up on the topic nor do I claim to be a security expert. This is just what came to mind when I had the same thought as you. Anyone else know for sure?
- cpeterso 11y agoThe client's hash is the password but the password file contains salted hashes of the client's hash. An attacker that has the client's password hash can replay it, but they don't know the user's password. An attacker with the password file doesn't know any clients' password hashes or whether any of the password hashes are reused by different users.
- sarciszewski 11y agoYo dawg, I heard you liked hashes... Meme reference aside, this is actually a sane way to do things.