4 ms·
If the Linode Manager database only stores the hash, how would they know the password? How did you find out about the illicit login?
by masterleep 11y ago
If the Linode Manager database only stores the hash, how would they know the password?
How did you find out about the illicit login?
- ceejayoz 11y agoIf they've been more compromised than something like a simple SQL injection vulnerability, it could be something like added code to log passwords or post them off somewhere else.
- stcredzero 11y agoIf the Linode Manager database only stores the hash, how would they know the password? Weak password? Weak hashing algorithm?
- Someone1234 11y ago> If the Linode Manager database only stores the hash, how would they know the password? Hashes can be turned back into plain text, it is just computationally expensive to do so. Hashing only slows down an attack (and or increases the cost), it doesn't not mitigate one. In particular if the hashes aren't salted then a rainbow table is an extremely effective way of breaking all of the hashes concurrently. The main method of doing so: Generate the hash for every combination of typable characters up to a given length (e.g. MD5() A-Za-z0-9 & specials up to 8x characters). This can be mitigated using a more computationally expensive hashing routine (or increasing the work factor on a less computationally expensive one) and salts. But given enough time OR computing power, all hashes will be broken. AWS makes breaking hashes a lot cheaper as you can bid on spare capacity and perform the operations relatively cheaply.
- alextgordon 11y agoThis only works if the input password has low entropy. You would think that people using Linode are savvy enough to be using long, randomly generated passwords.
- Someone1234 11y ago> This only works if the input password has low entropy. If you're generating every single possible password up to e.g. 8 characters the password's quality doesn't matter, only the length does.
- TheOtherHobbes 11y ago12 character random strings are an absolute minimum for a secure password, because brute forcing and tabling start to become impractical. Longer strings are even better. I wouldn't consider an 8 char password secure, no matter what the entropy is.
- Buge 11y agoYes length matters. That's why pretty much all "randomly generated" passwords are long. Mine are 20 characters.
- yeukhon 11y agoA good secure password hash should be generated with a salt to slow down the process, in addition to using strong (slow) KDF function like scrypt. State actor like NSA could have store all possible 8 character combination today in a massive storage facility. God knows. But the size of such rainbow table is only effective if there is no salt, as with salt the hash is now different despite the underlying password is the same, thus there will never be enough storage if salt is present. But the most effective "rainbow table"-like table is a look-up table with the followings: * leaked password in plaintext, associate with email and any ID (forum username??) * hash all of those passwords without salt * hashes (with salt) of known leaked passwords (you try pas$w0rd and found a match for some hash with salt) - this only works if your attack succeed. If you do a quick count you won't be surprise most passwords are fairly short and simple. If two complex passwords appear to be very similar, you can assume with a good probability they are used by the same person. You can learn some private data from just looking at password (e.g. birthday, pet's name, door number, company they worked for, sport team they root for, which many turn out to be the crucial hint or actual answer to security questions.) I have never opened or downloaded any leaked data and don't know if it legal for use at all, but the black market probably has over petabyte volume of such data available. It would be very interesting to see the whole world attack couple hashes per day. Imagine you go to a website, it gives you some plaintext, and you run a couple quick scrypt with random salt, and return the response. Now with a billion online users, run this every day once, you may end up finding one successful match of "this password == this hash with this salt" once in a while. But hey, that's what botnet can do...and then bitcoin!
- ryanlol 11y agoThey don't need to know the password with db write access. In fact, depending on how the sessions are managed the attacker might just need read access to log in without a password.