3 ms·
How come the salts aren't available? Did the attacker choose not to release them, or were they stored elsewhere?
by tonicoto 10y ago
How come the salts aren't available? Did the attacker choose not to release them, or were they stored elsewhere?
- Klathmon 10y agoOr were they really bad salts? Like a hash of the username?
- mnw21cam 10y agoThat wouldn't really be a proper salt, although technically it would fulfil the purpose of a salt, which is to prevent lookup tables being used.
- Klathmon 10y agoOh I agree, but I've seen too many "clever" systems which derive the salt from something like the username or another field or fields in the DB. Just because there is no obvious salt now doesn't mean it's not there. Only Dropbox knows how it worked at this point.
- tonicoto 10y agoWe will have to wait for a code leak ;-)
- bvinc 10y agoUh oh. You might be on to something. Salts are pretty much always stored right next to the hash, right? If the hack doesn't contain them, maybe they were doing something "clever" like that.