2 ms·
I guess you didn't read his notation in the beginning of the article that you should read his previous posts on the subject. The whole point is that you give on
by netzone 9y ago
I guess you didn't read his notation in the beginning of the article that you should read his previous posts on the subject.
The whole point is that you give only a part (5 first characters) of the hash (SHA-1 in this case if I'm not mistaken?) to the API, and you are then returned a list of passwords with the same first characters, then you check that response against the actual password.
In effect, Troy's service never knows the password. It doesn't even know if it existed in the list you received.