21 ms·
Or md5. I wouldn’t be surprised to see that from some in PHP land.
by CSSer 4y ago
Or md5. I wouldn’t be surprised to see that from some in PHP land.
- tkanarsky 4y agoHah, provide the hash and have the backend crack it whenever it needs to call the api.
- eloff 4y agoYou're not going to crack a hash for an API key. Not even with MD5. Long random strings are the worst case scenario for trying to reverse a hash.
- CSSer 4y agoI forget the exact details, but if I recall correctly you can crack md5 with a for loop in PHP because you can just iterate through the full character set. Maybe it would take awhile but having seen it in action for shorter examples I doubt that’s going to stop someone sufficiently motivated. Then again, at that point I guess they’d just opt for a tool like hashcat.
- mwint 4y agoThe full character set for an AWS key is super ridiculously huge, like heat death of the universe huge.
- CSSer 4y agoHm, could you provide one as an example? I’m kidding. That’s fair. I was just thinking of ASCII. How many services live up to AWS’ standards?
- eloff 4y agoAWS keys are ascii (hex encoded iirc), but they have so much entropy you could never guess it to reverse the hash.
- jamesfinlayson 4y agoOne I can see now is 40 characters of... not sure - I see uppercase, lowercase, digits and special characters. Maybe it's printable ASCII?
- bombcar 4y agoYour access keys consist of an access key ID (for example, AKIAIOSFODNN7EXAMPLE) and a secret access key (for example, wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY).
- selcuka 4y agoYou can find a collision, but you can't (unless you are very lucky) reverse the hash. The bits are not there.
- CSSer 4y agoOf course not. I’m referring to brute force. The idea that you can’t reverse a hash seemed so obvious to me that I didn’t feel it necessary to disclaim. You can increment characters in php like numbers[0]. It has some funny quirks. It doesn’t loop back around right away. If you write a for loop for that and pass it into the builtin for md5, you can just go until your hashes match. Of course this would take a long time for big hashes and there are other tools that can do this better if you’re motivated anyway. But hey, you can make a fun hash cracker in a few lines if you’re feeling it. My whole point was just that MD5 is fairly weak. Lots of people don’t or at least didn’t use to consider this because it was also (too) convenient. [0]: https://stackoverflow.com/a/3567245 https://stackoverflow.com/a/3567245
- selcuka 4y ago> I’m referring to brute force. The idea that you can’t reverse a hash seemed so obvious to me that I didn’t feel it necessary to disclaim. You are confusing hashing with encryption. There is no general way to reverse a hash, be it brute force or an algorithmic method. There are an infinite number of strings that will generate the same MD5 hash. My point is, your for loop may eventually find a string, but it won't be the original AWS secret, so it won't work.
- Godel_unicode 4y agoWith md5 hashes, the actual password isn’t there whereas base64 encoding is merely another way of representing the same bits. Yes md5 is weak, but it’s Fort Knox compared to base64.
- CSSer 4y agoI’m very much aware of the differences in format and effort. The idea was only tangentially related :/ Also, at the risk of being pedantic, yes, some semblance of the password is definitely there. Someone can happily go off and try to brute force it.
- Godel_unicode 4y agoAs long as we’re being pedantic, no they can’t (well, I guess they can try with no hope of succeeding?). You can find a sequence of bytes which will have the same md5, but you have no way of knowing that it’s the same string of bytes which someone else used to arrive at that md5. As I alluded to in my post, that information is gone.