4 ms·
What people always forget when they make statements about hashing being one way is that these algorithms are designed to be incredibly fast. So if what you’re
by jackjeff 3y ago
What people always forget when they make statements about hashing being one way is that these algorithms are designed to be incredibly fast.
So if what you’re hashing has low entropy/randomness (say a password) then you can totally brute force it.
In fact if there’s not a salt you can look it up in a rainbow table, saving yourself some compute. Googling a hash also works sometimes. If you want to brute force look at hashcat.
Something like SHA256 protects about 128 bits of entropy. If you go much lower than that, you’ll be brute forced. You can look at hashcat benchmarks online to estimate the time and money necessary to perform the attack. Anyone can crack an average simple password using a single round of SHA256 in no time.
- bluGill 3y agoFor passwords you often intentionally use an algorithm that is known to be somewhat slow. You want to rate limit passwords anyway and generally you should not be getting enough logins that an inefficient algorithm matters (if it does you apply denial of service protection not fix your password algorithm).