4 ms·
Nobody mentioned pepper yet. Not the "static salt" variant which you might find while googling. That is just more security by obscurity. I'm talking about addin
by eruquen 15y ago
Nobody mentioned pepper yet. Not the "static salt" variant which you might find while googling. That is just more security by obscurity. I'm talking about adding a random string of fixed length characters to the (salted) password that is not saved anywhere.
At login, it requires a bit of brute-forcing on the server to check the hash since we have to go trough all possible pepper strings. This adds a few ms (e.g. with a random string of length 4).
Now, on the attacker's side the picture looks drastically different. The amount of time required to brute-force through the already salted hashes grows exponentially with the length of the pepper string. If it takes a few days to crack the whole database without pepper, it might take a few years to do it with pepper. There is absolutely nothing the attacker can do about it. No access to any part of your system will help him or her.
- khafra 15y ago> Now, on the attacker's side the picture looks drastically different. The amount of time required to brute-force through the already salted hashes grows exponentially with the length of the pepper string. That isn't drastically different. The amount of time required scales exponentially with the pepper string for both the attacker and the legitimate authentication server. Not really different from increasing the work factor with bcrypt; and not as cool as increasing the circuit size with scrypt.
- eruquen 15y agoYou are right, I should clarify this. For the authentication server the time required jumps from close to nothing to a few ms. For the attacker, the time jumps from a few hours or days to a few years or decades. This asymmetry is what I meant when I said that it's a drastically different picture. Peppering is applicable to all hashing algorithms unlike the specific parameters you mentioned.
- IsTom 15y agoI haven't heard of this before, so I might be wrong, but I don't think it makes finding collisions any harder. It introduces expotentially many collisions in length of pepper. For example let's take xyzw and abcd such that h(xyzw) = h(abcd), now if you take peppered hash with length of pepper one you get hp(yzw) = hp(bcd).
- tptacek 15y agoThat's because it's a silly idea which is inferior to cryptographic adaptive hashing, as is done by bcrypt, scrypt, and PBKDF2. If you want to provide a work factor, use a real one.
- eruquen 15y agoFirst of all, you come off as condescending when you say "it's a silly idea" and say that the work factors you mentioned are "real" ones, thereby implying that adding more combinations is not a real work factor. Second, the actual usefulness of any work factor has to be proven first. Do we know that the iterative approaches offer "real" work factors? What if subsequent iterations are easier to compute by exploiting the structure of the input (i.e. password + result of previous iteration). We have to prove that this is not the case. The same argument holds for peppering, which is also based on computing hashes with a certain structure. I'd like to hear your arguments as to why certain work factors are more "real" than others, especially peppering.
- tptacek 15y agoI am absolutely intending condescension towards the idea. Since you're an anonymous user with almost no comments in your history, I do not concede the idea that it's even possible to condescend to you: I have no idea who you are. The usefulness of work factors has been proven. You can start here: http://www.bsdcan.org/2009/schedule/attachments/87_scrypt.pdf http://www.bsdcan.org/2009/schedule/attachments/87_scrypt.pd...
- deleted 15y ago[deleted]
- yukyukyuk 15y agoTo anyone who sees the above comment: this is a classic troll comment. The user 'tptacek' can't think of any flaws in this idea, but because it isn't his own, and because his inability to find any flaws causes him frustration, he feels the need to denigrate the idea by calling it "silly". It isn't particularly clear A) why the so-called "pepper" method would be inferior to some others and B) why it couldn't be combined with tptacek's suggestions. Even in tptacek's follow-up comment further down, there is still not even a single reason given as to why one of these ideas is inferior to another. If you are comparing ideas X and Y, and you think X is inferior to Y, you cannot demonstrate that fact to others by saying "Y is a great idea" because X may be an equally great idea, even if you think it is "silly" and you "condescend" to it. This is the difference between good writing and bad writing. A bad writer will tell you how to fell ("John and Cindy sat outside, watched the amazing sunset, and felt happy to be together") A good writer will make you feel something. Here is a cheesy example, this might work if you dig 90210, dubious in these parts, I admit. Or it just might induce nausea... ("John looked out at the sunset. Rays of light spilled through the clouds and over the rust-colored hills. A bird chirped twice in the distance by the lone birch tree before fluttering off. He could just barely make out a mark on on the tree. He turned to Cindy and asked 'Can you see it, where I carved our initials?' She looked out toward the tree and smiled. She looked over and cooed "Aww...", and then she snuggle-leaned into him.") Good writing is a lot of work, but the alternative is to look like a jerk /Fezzik