3 ms·
As someone extremely new to this; can this procedure be worked backwards to retrieve the original text? If no, why not?
by Curious42 10y ago
As someone extremely new to this; can this procedure be worked backwards to retrieve the original text? If no, why not?
- seanwilson 10y agoYou can't retrieve the original text because information is lost in the process and many inputs hash to the same value. However, if the range of inputs is relatively limited, you can try hashing inputs until you find the right hash (see rainbow tables for discovering user passwords from the hash value).
- _coldfire 10y ago>many inputs hash to the same value ? The chances of a sha256 collision is essentially zero barring a vulnerability being found in sha2. Far more likely for a comet to wipe out earth in your lifetime.
- xyzzyz 10y agoChances of practically finding a collision are indeed really small, though as you can easily calculate, there exists a sha256 hash value such that there are at least 2^256 different 512-bit long bit strings that map to it (and actually most of them should have this property).
- seanwilson 10y ago> The chances of a sha256 collision is essentially zero barring a vulnerability being found in sha2. Yes, but to answer the question if you can find the input from the hash, the answer is no because it's impossible to be 100% certain as many input can hash to the same value.
- contravariant 10y agoNot all operations are reversible, which makes it difficult to work out a simple inverse. Of course you could work backwards to find out which inputs could lead to a particular result, but this set of possible inputs would grow rapidly as you work your way back through the algorithm, making it nigh impossible to work out the original message, even if you have some idea what it's supposed to look like. Of course this is assuming that the hash algorithm doesn't have any weaknesses you could exploit.
- dorfsmay 10y ago> Of course you could work backwards to find out which inputs could lead to a particular result AKA rainbow tables, which explains why it is important not to use just a single word from the dictionary as a password. https://en.wikipedia.org/wiki/Rainbow_table https://en.wikipedia.org/wiki/Rainbow_table
- jessaustin 10y agoAs explained in your link, rainbow tables make salts important. Imposing arbitrary requirements on users is misguided.
- deleted 10y ago[deleted]
- blauditore 10y agoNo, one important property of hashes in security applications is irreversibility (except for brute force, i.e. try and error). For example, user passwords on a server should only be stored in hashed form (ideally with salt[1]). If an attacker gets access to that database, they will not be able to restore the original passwords without enormous computation costs. The "why not" is harder two answer and I don't know all the details either. But the general idea is that the hashing algorithm contains irreversible operations where multiple (intermediate) inputs would result in the same (intermediate) output, so you cannot derive a unique input from the output. A simple example for this is the modulo function: 9 mod 7 = 2, but also 16 mod 7 = 2. If you now see the result 2, the original number could have been 2, 9, 16, 23 or anything else of the form n*7 + 2. [1]: https://en.wikipedia.org/wiki/Salt_(cryptography) https://en.wikipedia.org/wiki/Salt_(cryptography)
- kelvin0 10y agoThis type of crypto hash is like hamburgers and cows (as a rather crude analogy): it's fairly easy to make a hamburger from the meat of the dead cow, almost impossible to make a cow from the hamburger meat.
- JohnStrange 10y agoIn theory yes. In practice no, because cryptographic hashes are designed to make this as hard as possible. AFAIK you cannot prove that they are secure, so it might be possible that known hashes can be broken entirely by using some breakthrough techniques of cryptanalysis. There is currently not much reason to believe such techniques exist, except perhaps for persistent rumors that the NSA is running some computationally very extensive operations (maybe with custom-built chips) that might be put to use for direct attacks on some weaker cryptographic algorithms like 2DES, RC4, SHA1, or 1024 bit RSA. That's pure speculation, though.