5 ms·
Maybe I'm misunderstanding (entirely possible!) and I think your point still stands, but isn't it 50M * 1,000 hashes * # of possible salts? EDIT: Just realized
by EvanKelly 13y ago
Maybe I'm misunderstanding (entirely possible!) and I think your point still stands, but isn't it 50M * 1,000 hashes * # of possible salts?
EDIT: Just realized that the salts have to be stored somewhere and the attacker probably grabbed those as well. I think that answers my question.
- mpyne 13y agoNo, because the salt is stored with the password. Salts are used to defend against reversing a password hash into a password, but they don't appreciably impede bruteforcing passwords into hashes.
- nwh 13y agoIt does mean that for a large dictionary attack things will go a lot slower. Rather than one computing one hash and comparing it to 50M hashes, the same word must be hashed with 50M different salts and then compared with their respective hashes.
- mpyne 13y agoThat's a more specific way of phrasing reversing the hash into a password, yes. ;)
- hexonexxon 13y agoYou can rent miners on the bitcoin network to use their pooled hashrate to break passwords, same with moxie's service cloudcracker.com
- rmc 13y agoSalts are used to make rainbow tables useless.