4 ms·
From the comments: > I do something similar via a shell > echo "masterpassword gmail" | md5 Please do not do this, md5 is not a cryptographic hash and is rel
by cjh_ 13y ago
From the comments:
> I do something similar via a shell
> echo "masterpassword gmail" | md5
Please do not do this, md5 is not a cryptographic hash and is relatively trivial to reverse.
Ie; is possible for someone to discover your 'masterpassword' given any one of your passwords generated via this method.
If one of your passwords is leaked then it is possible for an attacker to brute-force this to find out a list of possible 'masterpassword foo' combinations (although not knowing the length increases the search space).
If one of those foos is 'gmail' for your gmail password then it is game over.
Even if your foo is not similar to the service, if the attacker is able to get 2 of your passwords then the search-space is much smaller (looking only at the overlap of the reverse of both md5 functions).
This may not be relevant if you only take a 'random' sub-sequence from the generated md5, thus only disclosing part of the hash to the attacker.
- etler 13y agoPeople might not share my sentiment but I think doing this is fine. Yes, all your points are true, but they require the attacker to single you out specifically, and try and figure out your process. Frankly, unless you're a very important person to warrant someone singling you out, an attacker is going to go after the countless easier targets that do not require personal attention.
- cjh_ 13y agoOne assumption in security / cryptography is that the process is always known, otherwise it is security by obscurity. This is still better than password reuse as the plaintext doesn't disclose your other identified without further effort, however the users should be under no illusion of bullet-proof security.
- gtrubetskoy 13y agoAhem, md5 is impossible to reverse. The weakness of md5 is related to the ease with which one can find inputs that result in a specific hash, which does not apply in this case.
- cjh_ 13y agoI should have said 'possible to find the reverse'. For a given length it is possible to find all the inputs that could generate a possible hash relatively easy (cheap compared to other one-way-hashes).