2 ms·
"Q.md5 - to one-way-encode passwords etc. in insecure websites before sending to the server" This is a very bad advice which leads to a false sense of security
by dlsym 13y ago
"Q.md5 - to one-way-encode passwords etc. in insecure websites before sending to the server"
This is a very bad advice which leads to a false sense of security:
1. A fast hash function is not desired for hashing passwords. (Bruteforce)
2. There are TBs of rainbowtables for unsalted md5.
3. If you use a salt, you would have to expose it clientsided.
- EGreg 13y agoYou are most likely right. I should explain instead that the md5 should be used to verify HMACs sent by a service. However, when sending passwords over the wire, the client should ideally hash it and the username/email + id of the provider should be used as the salt. That way different providers can't impersonate a user on each other's servers. This salt SHOULD be applied on the client side even if you are using https, or you are actually trusting the provider to not misuse or leak your password, e.g. in logs. See for example http://blog.cloudflare.com/cloudflare-prism-secure-ciphers http://blog.cloudflare.com/cloudflare-prism-secure-ciphers
- cmircea 13y agoFast? I don't think a suitable word exists to express the speed of MD5 on GPUs, but here are the numbers: 8213.6 M/s, AMD 7970.