3 ms·
There's nothing to stop anyone from creating a reverse lookup table by systematically generating strings and their hash, and aside from dictionary words, this i
by deadowl 10y ago
There's nothing to stop anyone from creating a reverse lookup table by systematically generating strings and their hash, and aside from dictionary words, this is an example of low hanging fruit. It's a repeated sequence of characters, which would be the second most obvious heuristic (after the dictionary) when trying to generate plausible passwords and their associated SHA1 hash.
Before the LinkedIn leak, I was guilty of sharing passwords across sites, and I got a wake up call by a "someone tried resetting your password" email. Started resetting them all, got to the point where I noticed there were a lot and I should probably use a password manager. Eventually I found out I had over 100 online accounts for various things, all of them now having unique passwords. I've deleted a handful of them (e.g. MySpace, MyCokeRewards). There are a couple more I'm trying to get deleted (e.g. Dominos) but haven't been successful yet.
- roadnottaken 10y agoI thought salting was to stop precisely this sort of attack, no?
- deleted 10y ago[deleted]
- deadowl 10y agoFrom what I understand, salting prevents computing the tables ahead of time and the ability to cross-reference a single password hash against all other password hashes. It doesn't prevent people who have access to both the salt and the hash from performing the same attack against individual passwords.
- roadnottaken 10y agoYes, that sounds correct. I thought the idea, though, was to make the salt non-obvious for this reason. I would hope people aren't storing passwords in a table with a "salt" column, but I don't really know. But I think you're right: if you know the salts and you want to use this approach to go after a small number of high-value targets it could work.