3 ms·
I suppose the main danger is the possibility that someone might, at some point in the future if processing power should suddenly take a leap forward, come up wi
by drrob 10y ago
I suppose the main danger is the possibility that someone might, at some point in the future if processing power should suddenly take a leap forward, come up with a way to crack them.
- bbcbasic 10y agoWould something like an ASIC help the attacker, I wonder?
- drrob 10y agoOr some curious, thousands-of-computers strong grid-based cracking enterprise. I suppose, even constrained by the current state of tech, cracking bcrypt with some kind of massively parallel dictionary attack isn't entirely unfeasible.
- merb 10y agoeventually at least on PBKDF2 you could also increase the number of rounds taken. So if somebody logs in you could recalculate the PBKDF2 hash.
- drrob 10y agoIndeed, though I suppose you've got to hope that the keeper of the passwords gets their hands on a similar level of processing power as the attackers do, with which they can increase the encryption work factor.
- DasIch 10y agoYou can upgrade hashes offline as well. You just hash the existing hash with the new algorithm/configuration and remember algorithm, salt and any other parameters for all previously used algorithms. If you have all that information you can take the same path to verify the password and replace the chained hash with a simple hash that's faster to calculate.