3 ms·
I might have missed it, but there should have been a few caveats listed: 1) The size of the rainbow table can also be adjusted for password rules. (your passw
by AppSec 15y ago
I might have missed it, but there should have been a few caveats listed:
1) The size of the rainbow table can also be adjusted for password rules. (your password must have 1 upper, 1 lower, 1 number, 1 non-alpha numeric, no repeating characters, no in the dictionary, etc...)
2) This is a specifically brute force attack against a specific user. If you are looking at 1.7 days against an entire user store, the numbers don't look as promising. (note: this isn't a comment in favor of rainbow tables, just as point of interest).
3) A lot of sites still don't have salts/hashes done correctly.