4 ms·
I'm curious. How long could it take to bruteforce a JWT with an average latest generation i7 processor?
by milad_nazari 10y ago
I'm curious. How long could it take to bruteforce a JWT with an average latest generation i7 processor?
- vpol 10y agoToo long to waste time.
- brendanrius 10y agoDepends on the secret
- Freak_NL 10y agoDepends on the signing cypher or hash used. With SHA-256 or an RSA 2048 bit key pair this is not a vulnerability to be concerned about.
- wongarsu 10y agoSince brute forcing the HMAC is pretty much the same as brute forcing the underlying hash function, you would probably want to use a GPU instead of your i7. Using [1] as a reference for a specialised system in a price range affordable to hobbyists, assuming HMAC-SHA256, a 48bit secret would take about three hours to brute force (48bit is about 10 letters all lowercase), while a 64bit secret would already hold 25 years (assuming no upgrades etc). With sufficient volume you can probably build such a system for about $5000-$7000. Let's assume $5000, because that number is rounder. If you spend $1,000,000 on your setup (so certainly professional level now), your 64bit secret only holds 44 days. If the NSA would spend 10% of a single year's budget on GPUs, the resulting machine could crack a 64 bit secret in one hour, but a 84bit secret would take 100 years to crack (84 bits is about 17 lowercase letters, or 14 mixed-case, or 10.5 bytes if you use the entire range of the byte). Of course that ignores some scaling effects (if you spend $1billion you get much more bang for the buck by designing custom ASICs), but it should give a sense of what's secure against whom. By using proper 256bit secrets you should be secure against everyone until the end-of-life of your application. 1: https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a270c40 https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a27...
- milad_nazari 10y agoWow. Thanks, I learned a lot from this.