3 ms·
> are you really going to go through the trouble to cryptographically attack this weird password that doesn't work on other sites Of course you are, because t
by brl 17y ago
> are you really going to go through the trouble to cryptographically attack this weird password that doesn't work on other sites
Of course you are, because this password does work on other sites. All other sites.
With a single high end CUDA capable graphics device you can blow through 500 million MD5 operations in one second. How many words are in an English dictionary? Less than that.
That's how weak this is. If you steal the password database from bigforum.com, you can attack all the passwords in parallel. If you crack a password, you can then log into their facebook, gmail, paypal, whatever. This scheme pretty much guarantees you can do that.
- cdr 17y agoThat assumes you know people are hashing (or more specifically, which few passwords are hashed out of this enormous database you've stolen). How do you tell a random password from a hashed one as an attacker?