4 ms·
Theoretically stored passwords are not safe at all. Sooner or later they will get stolen if it is the case. Forgiva is actually big brother of kyle (https://gi
by marcusfrex 10y ago
Theoretically stored passwords are not safe at all. Sooner or later they will get stolen if it is the case.
Forgiva is actually big brother of kyle (https://github.com/esurharun/kyle https://github.com/esurharun/kyle) which has been at use for nearly 2 years and experienced and tested a lot.
Yes, you are definitely right on that we should put roadmap on webpage.
And no we are nor "nefarious" hackers neither junior NodeJS developers. :)
- danieldk 10y agoTheoretically stored passwords are not safe at all. What does this even mean? Aren't they as safe as the cryptography being used (key derivation scheme, encryption method, etc.)? (Of course, if a machine is compromised with a keylogger, it's pretty much game over anyway. Unless you use a hardware authentication token.)
- marcusfrex 10y ago>> What does this even mean? Again "theoretically" all encryption methods prone to brute-force attacks. And plus, encrypted storages indirectly reveals "encryption passwords" on succeeded attacks.
- kevhito 10y agoAnd if you go that path, "theoretically" an attacker might simply guess your password on the first try when attempting to log in as you, so password "storages" and "brute-force" has nothing to do it.
- marcusfrex 10y agoYou are mistaken on one think: it is not just being it "theoretically" possible but likeliness -or hardness- of it. If the possibility of an attacker guessing my password at first try is one in a billion -or trillion- chance, then we can say it pretty secure. But hacking a cloud with a possible zero-day flaw and cracking a password database is not that hard if we compare it with your example.
- kevhito 10y agoI was responding to this assertion: > all encryption methods prone to brute-force attacks The chance of succeeding within our lifetime with a brute-force attack against modern encryption is far less than one in a trillion. So in your words, it is far better than "pretty secure".
- minitech 10y agohttps://github.com/esurharun/kyle/blob/master/lib/kyle.rb#L112 https://github.com/esurharun/kyle/blob/master/lib/kyle.rb#L1... ret += Constants::PASSWORD_CHARS[c % Constants::PASSWORD_CHARS.length] Looks like biased output. Also, what is this? (From https://github.com/sceptive/Forgiva https://github.com/sceptive/Forgiva) algorithm forgiva-iterative-hashing Input: Value to hashed as DATA, Algorithm array AARRAY Ouput: Hashed input data final_value = DATA for each character C in DATA algorithm = AARRAY index of (C code num modulus AARRAY) final_value = forgiva-hash(final_value, algorithm) return final_value Is that selection of algorithms based on the hash? Doesn’t seem to jive with > It's developed by security professionals
- marcusfrex 10y agoIt generates underterministic way of calculation for a time-span of a successfull brute-force attack. Various hashing and encryption algorithms runs in different performance values. Thus, estimating for a CPU/GPU power or time range to attack Forgiva is more harder than other systems. Every master-key generates a different time and processor cost as you see. So this makes estimations fail for all attacking sessions.
- minitech 10y ago> Every master-key generates a different time and processor cost as you see. This is generally a bad thing and sounds like it will open you up to some kind of timing attack in the future. > It generates underterministic way of calculation for a time-span of a successfull brute-force attack. This doesn’t improve security and just adds unnecessary complexity.