40 ms·
Nope. Attacker can figure out "some" password (e.g. will find collision for specific salt+hash), that will be valid only for the server it already has access to
by seletskiy 11y ago
Nope. Attacker can figure out "some" password (e.g. will find collision for specific salt+hash), that will be valid only for the server it already has access too, so it's not the big deal.
All other nodes will have different salt+hash pairs, so brute-forced password will be not valid for them.
- akerl_ 11y agoI must be missing something, then: if you take input password A and salt/hash it individually for each server, and the attacker finds the valid input password A via brute force on one, why wouldn't it work on all of them? They aren't brute-forcing to find the salt or the hash, they're brute forcing input password A.
- asdfaoeu 11y agoThe attacker isn't going to find a collision that is not your password unless you are using a stupidly weak hash algorithm. The only input the attacker is likely to find is the original password and this is assuming it has less than 128bits of entropy.
- deleted 11y ago[deleted]
- MichaelGG 11y agoThat'd only apply if they're using very long, random passwords. For a 128-bit hash that'd be at least ~20 chars using the entire keyboard, and over 22 if alphanumeric only. Your docs mention SHA256/512, so double or quad those. If your attacker is able to "figure out" 128-bit+ passwords, then you've probably got other problems. And if the point of using passwords is for emergency logins from phones, I'm not sure how useful a 80 char pass is. Might as well keep the ssh key saved somewhere and type it in eh?