5 ms·
Hashed and Salted sha1 should take basically no time to crack at all.
by Navarr 10y ago
Hashed and Salted sha1 should take basically no time to crack at all.
- tedks 10y agoIt's my lay understanding this is true; there's a reason we all switched to bcrypt, right? But this comment is getting downvoted. What's the deal?
- alanh 10y agoIt is lacking in nuance, information, and clarity. (Surely a significantly strong password wouldn't be immediately cracked when hashed & salted, right? I don’t know for sure, and that comment isn't helping.)
- wavelattice 10y agoIf you read the article, it says the passwords are hashed and salted. So I think the comment is appropriate... I don't think this is the same thing as passwords being sold at all.
- tonmoy 10y agoThis was sarcasm right? In all seriousness though, I think titles like "passwords stolen" are a little misleading. Article titles should either be "hashed passwords stolen" or "plaintext passwords stolen" IMO.
- rudolf0 10y agoNo, he's absolutely right. Single-iteration SHA-1 is extremely inappropriate for password hashing, and all salting does is prevent rainbow table attacks and instant reversal of duplicate hashes. It does not slow down non-precomputed attacks one bit. It's much better than plaintext, but essentially only a little bit better than unsalted MD5. I'm really surprised Tumblr would use such an awful password storage scheme as late as 2013. I thought they invested a lot into security?
- vonmoltke 10y agoFrom the perspective of trying to crack a single user's account the salt does not slow down non-precomputed attacks at all. From the perspective of trying to crack the entire database, or a significant portion of it, it multiples the work required by N (where N is the desired number of cracks to perform).
- rudolf0 10y agoI mean, it depends how you look at it. I consider precomputed attacks a special case of these attacks, sort of. In the security world, most password-predicting attacks are linear with respect to the amount of accounts you're trying to get passwords for. It's true that it will take a lot of hardware to efficiently attack all 65 million passwords. But in my field, big dumps like these are a godsend when doing a pentest. Looking to compromise a sysadmin's account? Search his/her emails and aliases in as many DB dumps as you can find, then expend a lot of resources cracking that one hash. If it's just a SHA-1 hash and the password isn't very strong, you won't have much trouble. Also a risk for people with vendettas against specific tumblr users (which, to my understanding, is a big issue on tumblr).
- xyience 10y agoBrute force as an attack vector is dealt with by requiring "strong" passwords, not by using scrypt, so the thought of using a hash that protects all passwords equally with respect to the time it takes to try one, as an extra layer of defense for those weakest of the "strong" passwords, doesn't usually come up unless you're actually looking into how to design a login system instead of just copying from somewhere/some book as fast as you can and moving on. This issue with Tumblr that late doesn't surprise me at all. At least one major benefit of SHA over MD5 is that you won't trivially find collisions and thus compromise the accounts of even those users with strong passwords...
- deleted 10y ago[deleted]
- PaulyGlott 10y agoIn this case, it should be "Salted Password Hashes Stolen"
- pg_is_a_butt 10y agosalted with what? unique salts per password? hashed with what? in many cases you're 5 minutes away from plaintext passwords, so the distinction is meaningless.
- avar 10y agoIt still depends on the password. I've changed my Tumblr password after this just in case, but it was some approximately hundred character random password generated by Lastpass before that. So let's say half the ASCII range, which gives us this number of possible passwords: (2^7/2)^100 41495155688809929585124078636911611510124462322424368999956573296906\ 52811412908146399707048947103794288197886611300789182395151075411775\ 307886874834113963687061181803401509523685376.00000000000000000000 I'm pretty sure even if it's just stored as single-iteration sha1() cracking it would take until the heat death of the universe.
- Navarr 10y agoThat's a fair point, but I do not believe password managers are currently the norm for a userbase like tumblrs. Still, the hash time for a SHA1 is fairly insignificant at this point.
- pg_is_a_butt 10y agothe heat death of the universe, or until an attacker realized Lastpass has been breached multiple times, and they already have every password you've ever used with it. you're an: i\ d\ i\ o\ t.00000000000000000000