4 ms·
FTA: "Unlike the passwords taken from government contractor IRC Federal, the passwords from the Booz Allen system have been hashed using SHA-1. This will make b
by olsonjeffery 15y ago
FTA: "Unlike the passwords taken from government contractor IRC Federal, the passwords from the Booz Allen system have been hashed using SHA-1. This will make breaking into further systems using the released account information harder—but it's likely that at least some of the passwords will be crackable, and so further damage could follow."
<insert critique of prevailing orthodoxies re: password hashing, a horse beaten to death on HN already>
- matthavener 15y agoA lot of people will assume "hashed using SHA-1" means simply SHA1(salt + password) but in practice many password hashing libraries use SHA-1 with a work factor, similar to bcrypt. I think NIST currently requires at least 100,000 rounds of SHA-1.
- olsonjeffery 15y agoMy read of the original announcement on piratebay (sorry, link not handy) was that the group who made the release asserted that: 1) the passwords were unsalted 2) they had already recovered plaintext passwords has anyone followed up on this?
- trotsky 15y agohttp://news.ycombinator.com/item?id=2752711 http://news.ycombinator.com/item?id=2752711