3 ms·
It seems like you either didn't actually read the RFC or read but didn't understand, then made a fuss out of your ignorance. SRP uses SHA1, but not just that.
by cryptbe 14y ago
It seems like you either didn't actually read the RFC or read but didn't understand, then made a fuss out of your ignorance.
SRP uses SHA1, but not just that. Here is the relevant part of the RFC [1]:
The host stores user passwords as triplets of the form
{ <username>, <password verifier>, <salt> }
Password entries are generated as follows:
<salt> = random()
x = SHA(<salt> | SHA(<username> | ":" | <raw password>))
<password verifier> = v = g^x % N*
[1] http://www.ietf.org/rfc/rfc2945.txt http://www.ietf.org/rfc/rfc2945.txt
- zaroth 14y agocryptbe - I quoted the exact same text from the RFC in a post below. Sheesh... From this it should be obvious to you that what SRP is doing is no better than SHA1 for protecting against dictionary attacks. 'g' and 'N' are well known numbers (also posted below). Username, and salt are known. It's the perfect setup for high speed dictionary attacks. Please edit or delete your post. You can read my more lengthy post on this here: http://www.opine.me/blizzards-battle-net-hack/ http://www.opine.me/blizzards-battle-net-hack/