3 ms·
If the database leaked, the salt would become known. A truly anonymous system should still be just as effective if the entire DB is known to an attacker. Assum
by extrapickles 5y ago
If the database leaked, the salt would become known. A truly anonymous system should still be just as effective if the entire DB is known to an attacker.
Assuming there are on the order of 10 billion valid phone-numbers (there could be on the order of 100 billion depending on how far down the rabbit hole of international numbers you go). A GTX 1080 can do SHA512 @ ~1 billion/sec[0]. This means it will take 10 seconds (longer if you have a >11 digit number) to recover each phone number. This is fast enough that you don't need to bother hashing the phone book, you just brute force every possible number.
I would expect the napkin math to come out to years of compute to unmask someone in the face of a DB leak, not seconds or minutes.
[0]: https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a270c40 https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a27...
- bagels 5y agoWhy would the salt become known if it's also discarded? Do they need to re-hash the phone number a second time?
- extrapickles 5y agoAs far as I can tell they cannot discard the salt if they want to be able to tell if you already have a 'humanID'. Without the salt, you cannot tell if the phone number already has an account without having to brute force the salt. If they were serious about this, they should at least use scrypt or some other modern password hashing technique as salted sha512 can be computed too quickly on modern hardware.