3 ms·
Hash and salt
by addingadimensio 4y ago
Hash and salt
- galeaspablo 4y agoHow could I match an incoming unhashed value to an existing salted hash?
- m4jor 4y agohashcat
- ohbtvz 4y agoThere are only about 3 billion valid US phone numbers. How many hashes can your GPU compute per second?
- m4jor 4y agoMost people crack with multiple GPUs. For example, I have a 5 GPU (3080s) rig that I used for mining ETH but now can use to crack with hashcat. tl;dr crack fast af boiii.
- parker_mountain 4y agoBack of the hand math, and some benchmarking, suggests that a consumer laptop GPU from about 2015 could bang it out in a month. And, that's being (extremely) pessimistic. (Assuming a GPU takes .001s to do a sha3 hash, which is more than double the actual benchmarks). I would estimate that a single, high end GPU from the last or current generation could probably chew through it in under a week.
- DenisM 4y agoOne can easily devise a hash function that a GPU can only compute once per second. Or per year, even, although that would be impractical.
- kadoban 4y agoIf you salt, then either you can't lookup a number, or you've only changed the problem to: iterate over all the possible phone numbers, _add the salt_ and hash them. No big difference.
- nemothekid 4y agoThe salt doesn't buy you anything, given that Facebook also knows the salt.
- parker_mountain 4y agoWhile a secret salt is effective in the short term, it's an un-rotatable value. Which means, if the salt gets leaked, you are screwed (or rebuilding the entire table by brute forcing it, or adding another layer of salting - not great!). For a company operating at Facebook's scale, with their kind of scrutiny around handling PII, this is unfortunately functionally useless. For some data types where hashing isn't super effective, and where associative identifying information is attached (such as a user id), a more effective mechanism might be to encrypt the data with a strong random value appended, and decrypt to do the lookup. This would require a correctly provisioned HSM to do properly - the private key secrets should NEVER be exported. While hashing seems like a good idea, it's actually particularly and deceptively tricky for these kinds of use cases.
- lost_tourist 4y agoI would say it's better than doing nothing though.
- parker_mountain 4y agoIt's complicated. Your local security engineer might be wringing their hands about this. Definitely an avoid at any cost kinda situation.