4 ms·
>Password hash dumps are worthless if the password hashing scheme used is i)crypto-hashing based and ii) uses salt. >6-8 char passwords are not an issue under
by jere 7y ago
>Password hash dumps are worthless if the password hashing scheme used is i)crypto-hashing based and ii) uses salt.
>6-8 char passwords are not an issue under this scenario.
I don't think so. Unless you meant something other than cryptographic hashing when you say "crypto-hashing". SHA-256 is a cryptographic hashing function (much more likely to be used at a bank than something like bcrypt I would wager) and a GPU is going to do on the order of a billion hashes per second. So cracking a 6 character password in minutes.
A salt will make a set of passwords harder to crack en masse, but if they want your specific password, salting isn't going to make that any harder.