6 ms·
Why are they force resetting everyone's password if they are bcrypt'ed?
by 925dk 9y ago
Why are they force resetting everyone's password if they are bcrypt'ed?
- yarper 9y agothe most popular passwords are love, secret, sex and god
- jacquesm 9y agoDoes HipChat hash client side or server side?
- cypherg 9y agoit's considered best security practice to do so
- 925dk 9y agoBy whom?
- Godel_unicode 9y agoScience. You might find the below numbers interesting. Note that this performance is only one workstation with 8x gtx980. Even the mighty bcrypt (sidebar, look at the sha512 #s) won't save you if your password is bad. Now consider social media mining to enhance the word list. Now consider that (anecdotally) I have never done a hashcat audit and not had to have a conversation with someone about choosing better passwords: Hashtype: bcrypt, Blowfish(OpenBSD) Workload: 32 loops, 2 accel Speed.GPU.#1.: 6398 H/s Speed.GPU.#2.: 6507 H/s Speed.GPU.#3.: 6513 H/s Speed.GPU.#4.: 6643 H/s Speed.GPU.#5.: 6534 H/s Speed.GPU.#6.: 6512 H/s Speed.GPU.#7.: 6689 H/s Speed.GPU.#8.: 6542 H/s Speed.GPU.#*.: 52338 H/s https://gist.github.com/epixoip/c0b92196a33b902ec5f3 https://gist.github.com/epixoip/c0b92196a33b902ec5f3
- Jach 9y agoBcrypt isn't magic. It will help slow down a full crack against everyone when every pw takes some tens of ms to check (though even if they had a hefty work factor of 1 second on a beefy ec2 instance, you can check a million accounts for 'password' in 11.5 days on a single machine, much less when you can spin up many more instances / leverage a botnet of many if less powerful machines). And if you want to target an individual user, you can try a million different PWs on their account over the same period. That's why it's best practice for everyone to rotate, though if your PW is complex and you're not a particularly juicy target you can probably get away with not doing it right now.
- ams6110 9y agoCYA. If they didn't force resetting passwords, they would at least appear to not have done "everything possible" to protect the account.
- narsil 9y agoThe webserver could have been compromised causing plaintexts for login attempts to be exposed as well. In fact, that is a very plausible explanation for how the database was accessed since it is usually firewalled off.