4 ms·
Not really, because the exponential scaling with strength of password dominates the sub-linear scaling in quantity of passwords. The passwords in the dataset w
by bcoates 10y ago
Not really, because the exponential scaling with strength of password dominates the sub-linear scaling in quantity of passwords.
The passwords in the dataset will neatly divide into "trivial" and "intractable".
A single password with 80 bits of entropy (16 characters, random lowercase/numbers) will take more time to crack than 1,000,000,000 strong human-chosen passwords under 40 bits.
Most of the passwords will be so weak that it might not be worth doing the sorting and preprocessing needed for the parallel attack on multiple passwords with the same salt.
Once you're using just plain hashing you've already lost and instead of using ad-hoc salting schemes you should be using a proper PBKDF (PBKDF2, bcrypt, whatever)