5 ms·
In the article, it mentions that the password are hashed using SHA-512. As has been mentioned before, using such a fast hashing scheme for passwords is a terrib
by maximilian 15y ago
In the article, it mentions that the password are hashed using SHA-512. As has been mentioned before, using such a fast hashing scheme for passwords is a terrible idea. Any idea as to why they do it this way? (instead of using bcrypt)
- RyanKearney 15y agoBecause it just works.
- num1 15y agoYou're using an apple product. When did they ever claim to be secure? Your life is easier, more magical, full of glass, and very fast! Security is... a little bit of whipped cream on top. So enjoy your gestures on that magic touchpad, don't worry about being safe. (Sorry, I couldn't resist)
- tiles 15y agoApple doesn't ignore security, they advertise security enhancements in their products: "Address space layout randomization (ASLR) has been improved for all applications. It is now available for 32-bit apps (as are heap memory protections), making 64-bit and 32-bit applications more resistant to attack." "Application sandboxing protects the system by limiting the kinds of operations an application can perform, such as opening documents or accessing the network. Sandboxing makes it more difficult for a security threat to take advantage of an issue in a specific application to affect the greater system." Part of OS X Lion's new features: http://www.apple.com/macosx/whats-new/features.html#security http://www.apple.com/macosx/whats-new/features.html#security
- num1 15y agoErm... I forgot I was in a place where preemptively apologizing for making a joke isn't enough for people to think you're joking. I would like to point out though, that the text you just copied are pretty much apple's only words on the topic. To further my joke even more: Google search for "easy" on apple.com [1] returns 3.3 million results. Google search for "secure" on apple.com [2] returns .5 million results. On the internet easy returns 3.6 billion results, and secure 1.25 billion. So on the apple site, you would expect easy to show up 3 times as much as secure. In fact, easy shows up over 6 times as much as secure. This definitely proves apple cares about security only half as much as the rest of the internet does!
- starpilot 15y agoDoes netcraft confirm that?
- num1 15y agochecking netcraft is left as an exercise for the reader
- scott_s 15y agoThere's a difference between recognizing a joke, and thinking it's funny.
- num1 15y agoLet's see how much karma I can lose in one thread. There's a difference between not thinking a joke is funny, and arguing against it as if it weren't a joke, a la tiles.
- jessedhillon 15y agoI downvoted not because you joked, but because you made patently untrue claims and then backed them up with a very poor methodology. So poor that you can't simultaneously be smart enough to read and understand this site and dumb enough to think it's logical to argue this way. I conclude, therefore, that you're trolling.
- num1 15y agoI wasn't talking about the downvotes, that's to be expected. I was talking about the humorless replies :) If we all acted our IQs, all the time, the world would be a very boring place. It's not responsible to buy myself expensive toys, it's not respectable to be sarcastic. Yet we do it anyway. Trolling is meant to make people angry, I meant to to get a chortle out of at least somebody... but now I know, beyond a shadow of a doubt, that this is not the site for that. Thank you for helping me realize it.
- retanga 15y ago
- rmc 15y agoIt's bad, but it's not that bad. SHA is widely supported, and not that bad, yet. Also this is protecting desktop computers, where cracking hashes is not a common security problem. Getting the machine stolen in starbucks is probably much more common for this type of machine.
- nknight 15y agoMacs are not used exclusively as desktops.
- baconhigh 15y agoIt would be interesting to see if this was possible in OSX Lion Server.
- getsat 15y agoServer is no longer a separate product. I have Server installed on this desktop and the example command works as described.
- rmc 15y agoNo exclusively, no. But massively. I'd guess, what 90%, of OSX installs are desktop/laptop/residential market/
- lawnchair_larry 15y agoDespite all the ranting on HN about bcrypt, pretty much no one actually uses it. Not linux, not windows, not apple.
- hackermom 15y agoOpenBSD uses it :)
- KonradKlause 15y agoNo, OpenSUSE for example is using bcrypt. See: http://www.openwall.com/crypt/ http://www.openwall.com/crypt/
- pjscott 15y agoMost everybody uses some form of slow hashing. Bcrypt is a particularly secure and convenient form of slow hashing, which is why people recommend it so much, but there are other schemes possible. For example, you can take a cryptographic hash function and iterate it a few thousand times.
- zdw 15y agoApple uses a key strengthening algorithm on their passwords, similar in concept to Bcrypt - I think they've increased the number of rounds past the 1000 mentioned since this paper came out: http://people.cis.ksu.edu/~sakthi/src/data/filevault_sakthi.pdf http://people.cis.ksu.edu/~sakthi/src/data/filevault_sakthi.... If you've already compromised an account and have access as that user, it's likely that what you're going after isn't going to be their password... ... although, if you were to nab the password file and their keychain file (which contains passwords to other accounts that they access) which is generally encrypted with the same password (the system nags you if it's not the same), you could potentially do some real damage.
- dchest 15y agoThe paper is about FileVault, not user accounts.