3 ms·
Shouldn't "downloading and cracking encrypted passwords" be functionally impossible? This third party must have had atrocious practices.
by gundmc 2y ago
Shouldn't "downloading and cracking encrypted passwords" be functionally impossible? This third party must have had atrocious practices.
- lolinder 2y agoPresumably this is referring to him downloading one of many different data breaches that are out there, and yes, many of the services that have had their password databases leaked had terrible security practices. Couple that with password reuse across services by the victims and he'd be able to guess passwords for the services he was actually interested in based on the passwords he got from the data leaks. Also, note that the article is probably misusing the word "encrypted"—you usually hash passwords, not encrypt them, and plenty of services will have used a bad hash function or failed to salt their passwords, opening them up to easy brute forcing with rainbow tables [0]. [0] https://en.wikipedia.org/wiki/Rainbow_table https://en.wikipedia.org/wiki/Rainbow_table
- ziddoap 2y agoIt's not cracking in the sense of a mathematical breaking of the underlying crypto. It's cracking in the sense of like, hashcat. Using wordlists, common passwords, common patterns (1 on the end, substituting a with @, i with !, etc.) and other methods and seeing if you output something that matches something on the list of hashed passwords you downloaded.