4 ms·
How is Facebook getting the plaintext passwords to compare to their hashed user passwords? Since the passwords are 3DES encrypted, only adobe should be able to
by cdjk 13y ago
How is Facebook getting the plaintext passwords to compare to their hashed user passwords? Since the passwords are 3DES encrypted, only adobe should be able to do that.
They could just be using email addresses, but that seems rather blunt.
I'm not a huge fan of Facebook, but what they're doing does seem like an excellent idea.
- sp332 13y agoThe passwords were all encrypted with the same key, and ECB mode still leaks some patterns. Jeremi Gosney of Stricture Consulting Group was "fairly confident" of his decoding of many of the passwords. http://www.zdnet.com/just-how-bad-are-the-top-100-passwords-from-the-adobe-hack-hint-think-really-really-bad-7000022782/ http://www.zdnet.com/just-how-bad-are-the-top-100-passwords-... Edit: oh it's the same guy who has this beast of a cracking cluster! http://arstechnica.com/security/2012/12/25-gpu-cluster-cracks-every-standard-windows-password-in-6-hours/ http://arstechnica.com/security/2012/12/25-gpu-cluster-crack... Edit2: more details about how the decoding works http://nakedsecurity.sophos.com/2013/11/04/anatomy-of-a-password-disaster-adobes-giant-sized-cryptographic-blunder/ http://nakedsecurity.sophos.com/2013/11/04/anatomy-of-a-pass...
- taeric 13y agoI believe the question was more of how does facebook know it was the same password? My guess is this was a "lazy" calculation. That is, they had to get their users to reenter their password so they could check it then. (Make sense?)
- deleted 13y ago[deleted]
- sp332 13y agoThey said in the article, they took the plaintext from the Adobe leak and hashed it using their own login algorithm, then compared hashes. Edit: wait, must have been a different article. Oh well, I read it somewhere :)
- taeric 13y agoAh, that makes a ton of sense. I was thinking in the case of if a hashed database of passwords got leaked. If you know the scheme, you could do this sort of comparison at a login. But, yeah, overly complicated for this scenario, I believe.
- cdjk 13y agoTo be more precise, Facebook knows hash(random_salt, facebook_password), and could do a check on the actual facebook_password when a user logs in, but I assume that it's not stored. Everyone knows encrypt(key, adobe_password), since that was what was leaked, and presumably adobe still has the key, so they know adobe_password. Facebook wants to determine if facebook_password == adobe_password. Without the key, that's impossible. And I think 112 bit keys as provided by 3DES are still secure, even considering an adversary with the resources of Facebook. A lot of the articles analyzing the adobe passwords seem to be comparing known-common passwords, passwords hints, and the insecurities of ECB-mode, which doesn't really scale. It seems like it would be better for facebook to just have a blacklist of common passwords (123456, password, etc), although then I suppose they don't get credit for pro-actively responding to a password leak (note: I'm not claiming that's why they're doing it - it seems like a good response, and I'm genuinely curious how they're doing it). Edit: I just thought of way they could do it. Generate a histogram over the first 8 bytes of each encrypted password. Pick a threshold (e.g. 2, or 10, but you'd have to look at the data to get a good number) above which the password is considered "common" and therefore insecure. Go through the list of email addresses in the adobe dump that have a "common" password, and if there's a facebook account with that email address force a password reset. That seems like it would work fairly well, and doesn't require any knowledge of the plaintext passwords.