4 ms·
> How is the timing here relevant to attacking shacrypt? By observing the time on the CPU it takes for the password hashing algorithm to complete, you can lear
by atoponce 8y ago
> How is the timing here relevant to attacking shacrypt?
By observing the time on the CPU it takes for the password hashing algorithm to complete, you can learn the length of the password. It's a side-channel timing attack.
But, as mentioned in the post, it's a negligible concern. In the case of md5crypt, the algorithm processes the password in 16-byte blocks. For standard 8-bit ASCII, this is 1-16 characters. Knowing that the bulk of user passwords are 7-10 characters, we aren't really learning anything anyway. We're not assuming here the adversary has the salted password hash. We're strictly talking about observing running processes on the machine.
> The run time does not depend on the length of any secrets here.
For md5crypt, sha256crypt, and sha512crypt, it does. sha256crypt will hash a 10 character random password faster than a 35-character Diceware passphrase. That's the whole point of the post.