3 ms·
You wouldn't encrypt/hash it, since 4-5 letters (say 30 bits) is trivial to brute force anyway. Talking about offline password encryption/hashing is a bit of a
by y7 6y ago
You wouldn't encrypt/hash it, since 4-5 letters (say 30 bits) is trivial to brute force anyway. Talking about offline password encryption/hashing is a bit of a red herring anyway, since it distracts from the fact that you're still sending your full password to the server for verification each time, so if the server is compromised for any length of time your password will be as well. Reusing passwords is broken: you really need different passwords for every service, and then it doesn't really matter whether the server stores them in plaintext.
Asking for random letters is a poor man's version of a zero knowledge proof. It's only marginally more secure than asking for the full password (if you want to break into an account you need to observe someone entering the password a few times instead of just once), at the cost of a very crappy user experience.
- kevincox 6y agoA lot of these sites will even change the letters they ask for every time you reload the page. So the number of observations is probably less than 10. Maybe 1 if you have access to decent chunk of IPs (assuming they will block you if you reload the page too many times).
- jesboat 6y ago> you're still sending your full password to the server for verification each time, so if the server is compromised for any length of time your password will be as well. The key difference between storing plaintext passwords and hashed passwords is that with hashed passwords, you can only compromise users who log in during the interval when the system is compromised, and even then, only for worse compromises (eg if all the attacker gets is arbitrary disk read, compromising hashed passwords would be impossible in most scenarios.)
- heavenlyblue 6y ago> users who log in during the interval when the system is compromised Why only then?
- SAI_Peregrinus 6y agoBecause the server doesn't store the password, only the "password hash" of the password. So if the server isn't compromised during the login there's no way for the attacker to learn the password itself.
- Siira 6y agoCan’t the hash be computed through some browser API? The browser can then visually show when plaintext passwords are being sent.
- y7 6y agoIf you're willing to rely on client-side code for authentication, there are better mechanisms, such as https://en.wikipedia.org/wiki/Secure_Remote_Password_protocol https://en.wikipedia.org/wiki/Secure_Remote_Password_protoco... There is a standard for it, called TLS-SRP, but unfortunately no browser supports it.