5 ms·
Whats stopping someone from creating a list of what strings trslate to each hash
by trisimix 9y ago
Whats stopping someone from creating a list of what strings trslate to each hash
- jaccarmac 9y agoSalt.
- mundo 9y agohttps://en.wikipedia.org/wiki/Salt_(cryptography) https://en.wikipedia.org/wiki/Salt_(cryptography)
- Recursing 9y agohttps://github.com/crypto101/book/blob/master/Crypto101.org#modern-attacks-on-weak-password-systems https://github.com/crypto101/book/blob/master/Crypto101.org#... While that was true before GPUs >To a modern attack, salts quite simply don’t help. Everybody should really move to key derivation functions (ideally scrypt)
- thisacctforreal 9y agoWhat parameters do you recommend? Is N=14, r=8, p=1 good enough?
- nyxxie 9y agoThe usual answer is to choose the parameters in such a way that targets the largest verification time that your servers can stand. I'm not aware of a recommended minimum value. In general, though, you're making a pretty good choice by choosing bcrypt, and so long as you're using the above you should have far better security as compared to sha*/md5/etc
- jsjohnst 9y agoHashcat running on a Amazon p3.16xlarge (8 Nvidia Tesla V100 GPUs) does 115 BILLION salted SHA-1 hashes per second. Based on that, most weak passwords are cracked in seconds, even if you have per user salts.
- thisacctforreal 9y agoBTW this is called a Rainbow Table :)