3 ms·
As others have pointed out, the use case for pasting plain text passwords is not quite clear. Maybe it would be a good idea to allow searching for hashes only,
by mbid 9y ago
As others have pointed out, the use case for pasting plain text passwords is not quite clear. Maybe it would be a good idea to allow searching for hashes only, or at least hash the password in js on the client.
Also, I'm genuinely curious as to why SHA-1 is used and not SHA-256. Surely the one-time additional cost of using SHA-256 would've been negligible for Troy?
If at some point somebody manages to do preimage attacks on SHA-1, I have to assume my password is broken if I've submitted its hash to his API. Although I guess you'd have to actually be able to enumerate preimages, preferably from small to big. Still, I don't understand why Troy doesn't account for the possibility by using a hash function widely considered to be stronger.
- tracker1 9y agoI believe the sources for the data breaches were mentioned in the article, so if someone wanted to get those sources anyway, it wouldn't be a big deal.
- bigiain 9y agoHe stops well short of saying "here's a link to the pastebin dumps!", but yeah - it wouldn't take too much google-fu to build your own version of this - perhaps not a 300M entry one, but I doubt it'd take more than a weekend to get halfway there if you wanted too.