6 ms·
hmmm... public User signin(String username, String password) { String pwd = EncrypKit.md5(username + password); return model.select().eq("username",
by dodyg 11y ago
hmmm...
public User signin(String username, String password) {
String pwd = EncrypKit.md5(username + password);
return model.select().eq("username", username)
.eq("password", pwd).fetchOne();
}
- tobyhinloopen 11y agoGotta love them securitie
- tluyben2 11y agoYou mean: as framework creator you should make your documentation reflect the latest security standards right? Just to make sure.
- onion2k 11y agoI think dodyg's point is more that someone using MD5 as a password hash is unlikely to have created a modern, secure, well-designed framework. If there's a problem as significant as poor password security then there's very likely to be other more subtle problems as well.
- mikkom 11y agoAs I'm not up to the current security research, what is problem with using md5 hash of name+password? Is the missing salt problem you are refering to? Brute forcing md5 is easier than some other hashing algo because of collisions? (And I would disagree that knowing that how to properly hash passwords means that the whole framework itself is poorly designed)
- jfim 11y agoMD5 is pretty cheap to compute. According to this Stack Exchange post[0], a GPU can do billions of hashes per second, so a short/weak password would be quickly cracked. [0] http://security.stackexchange.com/questions/38134/what-are-realistic-rates-for-brute-force-hashing http://security.stackexchange.com/questions/38134/what-are-r...
- mikkom 11y agoIf someone has local access then it's easy to crack any passwords (of any hashing algo). However if the cracker has local access and/or full access to DB then weak password hashing is one of the least problems.. Making password checking slower is very easy if the cracker doesn't have local access. Just sleep for XXX ms at every hash check and double it for every incorrect attempt (per IP).
- superuser2 11y agoPassword hashes are stolen in a variety of ways, when attackers find a way to dump arbitrary files or get results of arbitrary SQL strings, even one byte at a time. Yes, if that happens the site is toast, but 99% of its users have used that password somewhere (everywhere) else. That's not your fault, but using a better hashing algorithm is so trivial that it makes you an asshole to betray your users like that.
- mikkom 11y agoOkay so the original comment was probably about cracking MD5's then. Thanks for clarification as this was not clear from the original comment.
- superuser2 11y agoMD5 is cheap enough to brute force now that we're talking "moderate annoyance" instead of "heat death of the universe" territory.
- onion2k 11y agoSpeed is the problem. ocl-hashcat can test in the region of 6 billion MD5 hashes a second on a decent GPU. With a random salt and, say, an 8 character password it'd take a long time, but not so long it's impossible. On a site that includes rules like 'Must have an uppercase letter', 'Must include a number', and 'Must include a special character' you actually reduce the size of the space and consequently make the password easier to brute force. With those rules in place there's 159,655,911,367,680 possible passwords[1], so brute forcing at 6 billion hashes a second it'd take just over 7 hours. Maybe double that for the overhead of adding in the salt and managing the list of attempts, etc. The point is it's achievable. If someone gets a dump of the database it can be turned back in to usable accounts. If you use something much slower they can't. There's no benefit to using MD5. On the other hand, using a better hashing algorithm protects user's passwords from brute force attacks. Why wouldn't you want that? Quite a good article about cracking a well designed database of bcrypt'd passwords - http://arstechnica.com/security/2015/08/cracking-all-hacked-ashley-madison-passwords-could-take-a-lifetime/ http://arstechnica.com/security/2015/08/cracking-all-hacked-... [1] From http://math.stackexchange.com/a/410885 http://math.stackexchange.com/a/410885
- mikkom 11y agoOkay I understand this much better now. I was assuming this was about remote access exploit not a local one. Point taken. Use SHA-? instead of MD5.
- onion2k 11y agoYep. SHA-256 is a good bet at the moment, or SHA-3 if it's an option.
- franciscop 11y agoNot really, bcrypt is the only bet, SHA-256 is also too fast
- mudetroit 11y ago
- sah2ed 11y agoIf you haven't already, you should consider opening a pull request.