3 ms·
I accidentally up-voted parent, so felt I had to reply since this part is somewhat wrong: > Using multiple salts would seem to help defeat brute forcing or dic
by sorbits 15y ago
I accidentally up-voted parent, so felt I had to reply since this part is somewhat wrong:
> Using multiple salts would seem to help defeat brute forcing or dictionary attacks, but that is only true if the salts are secret
If I have a dictionary of common passwords, I need to hash this with the salt used by MtGox and then I can test the hashes against all the passwords from MtGox.
Had they used a different salt for each password, my work would be n times as expensive (n being the number of passwords to test against).
- gvb 15y agoUsing multiple salts makes it more expensive, but it doesn't defeat an attack unless it makes the attack impossibly expensive. My contention is is that multiple salts by themselves will not make the attack impossibly expensive. Better encryption, e.g. bcrypt http://en.wikipedia.org/wiki/Bcrypt http://en.wikipedia.org/wiki/Bcrypt attempts to make it impossibly expensive to crack passwords. Part of their technique is to use per-password salts to increase the time for all passwords, but the key is to have an encryption algorithm that takes an "impossibly" long time per password as well. Key is that it is "an adaptive hash: over time it can be made slower and slower so it remains resistant to specific brute-force search attacks against the hash and the salt." Rainbow tables are O(1). Salts are O(n). Bcrypt is O(big), where "big" can be increased to keep it bigger than a "practical" attack will be willing to attempt.
- DennisP 15y agoGiven that the bitcoin protocol adjusts the difficulty of block generation, it's kinda ironic that mtgox didn't use bcrypt.