7 ms·
I don't know if the creator is going to see these comments but lamernews.com goes to a GoDaddy parked domain page. Not sure if DNS changes just need to propagat
by coderdude 15y ago
I don't know if the creator is going to see these comments but lamernews.com goes to a GoDaddy parked domain page. Not sure if DNS changes just need to propagate or what.
- jonpaul 15y agoI agree completely... I was hoping to see a live version. Live versions can help OSS spread and generate hacker interest. However, it should be noted that I'm thankful that the author decided to share this.
- antirez 15y agoHi Jon! here it is almost the contrary, I wrote the code especially to run it as a real service. It is just that it needs a few more days. But actually... I can just run it easily in a server of mine just to show it to you. Let's try to install it... just a moment.
- oppegard 15y agoHere it is running on Cloud Foundry: http://lamernews.cloudfoundry.com http://lamernews.cloudfoundry.com
- antirez 15y agoHi, this is just the first public release. Hope to get more features inside and more testing before actually installing the first version into lamernews.com. The code base got just a few days of after-work hacking, so probably this will take a few more days to be ready. Thanks for the hint.
- daeken 15y agoJust noticed you're using a single pass of SHA1 (salted) for password storage. Would you be opposed to a patch using a safer password storage mechanism? If not, I'll throw one your way in a couple hours.
- antirez 15y agoif what you are thinking about is to use blowfish or other algorithm with a slow key scheduling step, what about if we just reiterate N times SHA1? Should be exactly as secure, like in: SHA1(SHA1(SHA1(0|pass)|1)|2) and so forth. This way there is no requirement for an additional library.
- daeken 15y agoI would strongly recommend that rather than doing that, go with standard PBKDF2. In essence, HMAC(HMAC(HMAC(...(password)))) with a per-user salt. I generally recommend 10k+ rounds with PBKDF2 (each one is cheap). This wouldn't give you an additional dependency and is super easy to put in place -- I'll do it, if you want.
- codahale 15y agohttps://github.com/emerose/pbkdf2-ruby https://github.com/emerose/pbkdf2-ruby
- pjscott 15y agoIf you concatenate your password and a salt, then iterate a cryptographic hash like SHA256 a few thousand times, this is almost exactly PBKDF1. It's a good, respectable password hashing scheme. The main advantage that PBKDF2 offers is the ability to produce arbitrary output sizes. (The difference between this and PBKDF1 is that PBKDF1 requires using either MD2 or SHA1 as the hash function, and hasn't been updated to reflect the availability of SHA-256 and SHA-512.)
- antirez 15y agoNote that PBKDF1 is exactly that, vanilla chaining of the same hash function. And AFAIK is not believed to have known attacks, with the only drawback being the fixed output size. I guess that the xor approach used in PBKDF2 is useful since you want to compute T1, T2, T3 ..., Tc that are multiple output blocks all starting from the same input, so this gives more information to the attacker and the schema is designed to avoid showing some "state" that is possible to more easily analyze. Not sure, but the point is, I don't think PBKDF1 is unsafe either, and it is just chaining.