4 ms·
There's still the question of why he would need the password hashes. Assuming he wanted the plaintext passwords to see if they are 'complex' and 'strong,' he wo
by sdkmvx 15y ago
There's still the question of why he would need the password hashes. Assuming he wanted the plaintext passwords to see if they are 'complex' and 'strong,' he would have a hard time telling that from the hashes.
5f4dcc3b5aa765d61d8327deb882cf99 and 05b28d17a7b6e7024b6e5d8cc43a8bf7: Which is a dictionary word and which is a string of punctuation? (I didn't salt :))
- 16s 15y agoPlease. 16Crack broke these in less than 5 seconds. Plain md5. 05b28d17a7b6e7024b6e5d8cc43a8bf7 = !@#$%^&*() 5f4dcc3b5aa765d61d8327deb882cf99 = password
- sdkmvx 15y agoYep. But they are hex strings that look like (are) hashes, and that's all I need to make the point. Next time I'll use /dev/urandom for that :) In a real scenarios, use PBKDF2 or bcrypt!
- MostAwesomeDude 15y agoJohn says the first one is "password", in under a second. I'll wait for a few hours to see if I can get the second one speedily. (By the way, this is why you shouldn't use MD5!)
- ominous_prime 15y agomd5 doesn't have anything to with it. sha256 maybe takes 10% longer to compute the hash.
- robtoo 15y agogrand-parent's point is presumably that bcrypt (or similar) is a better choice than md5.
- kingkilr 15y agoWhich is useful if you're brute forcing, md5 is also algorithmatically broken AFAIK.
- tomjen3 15y agoDefine broken. It is possible to generate (within reasonable time) two files which have the same md5 sum, which means you shouldn't use it to sign anything somebody else have given you. On the other hand collisions between two different files are still not something you would ever expect to see in the wild so if you are trying to find duplicated files, then you don't have to worry.
- burgerbrain 15y agoNo, that extra 10% doesn't mean shit against a brute force attack. As others have stated, use PBKDF2 or bcrypt.
- sdkmvx 15y agoYou're right. I would never advocate using MD5. Use PBKDF2, bcrypt, etc! I just needed some hex strings to make my point about the hashes (hopefully) not being reversible to the actual password, and thus useless for the purposes of seeing if the passwords are 'strong.'