5 ms·
Its [Current Year] and [Semi-Respectable Tech Blog] still doesn't know the difference between encryption and hashing.
by skyrw 10y ago
Its [Current Year] and [Semi-Respectable Tech Blog] still doesn't know the difference between encryption and hashing.
- knweiss 10y agoQuote: "Dropbox was moving away from using the encryption algorithm SHA-1"
- skyrw 10y agoI know the article explicitly and consistently says 'encryption' everywhere. I simply cannot fathom that they were encrypting instead of hashing. While I suppose it's possible that the SHA-1 versions were encrypted, I refuse to believe that the dropbox security team would transition from that to bcrypt 2-directional encryption over bcrypt 1-directional hashing. With that assumption I find it safe to say the tech journalist is being inaccurate.
- Mahn 10y ago> Because Dropbox stores its user passwords encrypted [...] > [...] batch of encrypted passwords [...] > [...] from using the encryption algorithm SHA-1 > Some of the stolen passwords were encrypted with SHA-1, while 32 million were encrypted with bcrypt > The passwords were also secured with a salt, a random data string added to strengthen the encryption. > it does not appear that the encryption protecting them has been cracked. I know it's completely tangential and I'm just nitpicking but damn that does bother me more than it should.
- roel_v 10y agoDoes it matter in this context? What tangible benefit is there for end-use, those that need education the most, to know the difference?
- bo1024 10y agoI think everyone should know what password hashing is. You wouldn't buy a car without airbags.
- oneloop 10y agoYou wouldn't have an e-mail account without authentication. You WOULD have an e-mail account without knowing how password hashing works. You WOULD buy a car without knowing how airbag works. If you think you know everything about every aspect of everything you interact with, you're so clueless you don't even realise.
- pop8row9 10y agoThis reply seems a little unhinged in comparison to the preceding comment.
- oneloop 10y agoThe preceding comment suggested that using a website without understanding authentication is like buying a car that has no airbags. That's unhinged. You know those "IQ tests" where they go "the foot is to the leg like the hand is to the..." type analogies? This person would fail hard.
- bo1024 10y agoI think it's worth making a distinction between knowing what password is and knowing how it works. I just think it should be on the list of security features of a service just like airbags should be on the list of features of a car, and people should have some idea of what it is and why it's important to have. Of course, any site can claim to have hashing but not actually do it or implement it terribly. The same is true for airbags, but for that we have regulations....
- tdkl 10y agoBecause $deity forbid that someone would actually learn something when reading news.
- wtbob 10y ago> Does it matter in this context? Yes, yes it matters. Correctness matters. Falsehood is wrong.