4 ms·
> The algorithm and salt are irrelevant. Given any input domain, you can choose an algorithm that will make bruteforcing the entire domain take as long as you
by SEMW 10y ago
> The algorithm and salt are irrelevant.
Given any input domain, you can choose an algorithm that will make bruteforcing the entire domain take as long as you like. As an extreme example, bcrypt with a work factor of 20 takes over a minute to calculate a single hash on a high-end desktop. (Of course, whether whatsapp are actually doing any of this is another question).
- JshWright 10y agoOk, there is no _practical_ algorithm that would matter for a keyspace this small. Assuming they are hashing the values at all, I think it's pretty unlikely they are using a high work factor KDF...