3 ms·
This is a bad idea which has been implemented a half dozen times. It's vulnerable to using a dictionary attack to recover the master password from a stolen has
by brl 17y ago
This is a bad idea which has been implemented a half dozen times. It's vulnerable to using a dictionary attack to recover the master password from a stolen hash.
It's also a particularly bad implementation that uses a single round of HMAC-MD5, which is a kind of bizarre primitive to use for hashing a password in the first place.
- cduan 17y agoYou know that old saw about your friend putting running shoes on as an angry bear approaches--he doesn't have to outrun the bear, he just has to outrun you? This password hashing is kind of like that. Sure it's easy to break. But if you're running a phishing site, are you really going to go through the trouble to cryptographically attack this weird password that doesn't work on other sites, when you've already got a bunch of other people's passwords that do work? For that matter, this solution is probably even more complicated than it needs to be. Just tack on the domain name wholesale to the end of the password, and you'll foil any automated phishing password script well enough.
- Shakescode 17y agoAren't you really arguing for a variety of "security by obscurity"? Yes, it may work for the immediate present, but it's hardly planning for the future, is it?
- brl 17y ago> are you really going to go through the trouble to cryptographically attack this weird password that doesn't work on other sites Of course you are, because this password does work on other sites. All other sites. With a single high end CUDA capable graphics device you can blow through 500 million MD5 operations in one second. How many words are in an English dictionary? Less than that. That's how weak this is. If you steal the password database from bigforum.com, you can attack all the passwords in parallel. If you crack a password, you can then log into their facebook, gmail, paypal, whatever. This scheme pretty much guarantees you can do that.
- cdr 17y agoThat assumes you know people are hashing (or more specifically, which few passwords are hashed out of this enormous database you've stolen). How do you tell a random password from a hashed one as an attacker?
- karanbhangui 17y agoWhat you say seems to be completely valid. However, I'm curious why 5 Stanford security experts seem to have not realized this? Honest question, not trying to use it as a way to disprove what you're saying (since I agree with you).
- lhorie 17y agoWhat if instead of this: hash(password + domainName); it did this? salts.put(domainName, randomString()); hash(password + salts.get(domainName));