5 ms·
I can confirm that the alleged dump is the real deal. Some passwords are md5 hashes, some are salted md5 hashes (utilizing the crypt[0] function). I did not lo
by soult 15y ago
I can confirm that the alleged dump is the real deal.
Some passwords are md5 hashes, some are salted md5 hashes (utilizing the crypt[0] function). I did not log in for a long time and my password was still unsalted, so I assume that converting to salted passwords was done either automatically on login or on password changes.
0: http://www.kernel.org/doc/man-pages/online/pages/man3/crypt.3.html http://www.kernel.org/doc/man-pages/online/pages/man3/crypt....
- bradleyland 15y agoI hate to look down my nose at other programmers, because I understand that we all start somewhere, but if you are building a financial exchange and you encrypted passwords using unsalted MD5 at any point in the history of your product, you have proven to me that you are learning as you go, and there is no way in hell I'd trust you with any significant sum of money.
- Hawramani 15y agoWhere do programmers learn about this stuff? Is it taught at schools? Can anyone recommend good books on proper security procedures?
- defrost 15y agoA good start can be made by following the work of Ross Anderson and having a read of his book. http://www.cl.cam.ac.uk/~rja14/ http://www.cl.cam.ac.uk/~rja14/ http://www.cl.cam.ac.uk/~rja14/book.html http://www.cl.cam.ac.uk/~rja14/book.html
- bradleyland 15y agoBeing a programmer means committing yourself to a life of continued education. Building a secure authentication system? Time to read up on the subject. You don't have to go far before you learn about the vulnerability of MD5 hashes for password storage.
- michaelf 15y agoA great place to start is "Applied Cryptography" by Bruce Schneier. http://www.schneier.com/book-applied.html http://www.schneier.com/book-applied.html Edit: Note, this really barely scratches the surface for building secure software. AC says how to apply cryptographic primitives correctly. It won't teach you how to avoid vulnerabilities specific to particular application domains (like CSS, SQL injection, etc...).
- marshray 15y agoThat book is old, and though still basically correct, there's much better ways to learn about the practice of developing secure systems. I recommend "Cryptography Engineering" by Ferguson, Schneier, Kohno which is a more modern descendant of Schneier's AC.
- michaelf 15y agoLooks like I need to update my bookshelf. Thanks for the recommendation.
- nokcha 15y agoFor web security, I'd recommend checking out this question on Stack Overflow: http://stackoverflow.com/questions/72394/what-should-a-developer-know-before-building-a-public-web-site http://stackoverflow.com/questions/72394/what-should-a-devel... Also the OWASP top ten vulnerabilities: https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Proje...
- rmc 15y agoWebsites like this are great. Just look at what other learned people here are saying about cryptography.
- wcoenen 15y agoTo give some context, that financial exchange had a trading volume of less than 1000 dollars/day six months ago. http://i.imgur.com/HHlnd.png http://i.imgur.com/HHlnd.png The original author sold the site in March before things got really serious.
- jpiasetz 15y agoMy account is also in the list and appears salted. Someone just tried to access my gmail account via an ec3 instance so I bet the salting is done wrong or something else.