8 ms·
Nor do they likely salt (I hope they at least hash) their passwords.
by dokument 12y ago
Nor do they likely salt (I hope they at least hash) their passwords.
- deleted 12y ago[deleted]
- nostromo 12y agoSalted passwords are not susceptible to a rainbow table, even if the salt is known by the attacker.
- ghshephard 12y agoRainbow tables went out of style in the early 2000s. GPU password hacking resulting in them being somewhat less useful than they were in the 90s.
- ayrx 12y agoOr you know... a simple dictionary attack. Salts aren't magic fairy dust that stops weak passwords from being brute forced.
- csirac2 12y agoTrue. The real problem is if you use a hash that's not designed for protecting passwords and can be computed at a rate of millions/billions per second on commodity hardware - versus s-crypt & friends which should only allow for 10s-100s guesses per second on the same hardware.
- ninkendo 12y agoSalt doesn't work that way... you're supposed to randomly generate salt for each hash and store it alongside the hash itself. (Authentications are done by hashing the password and salt together, and then comparing that to the stored hash.) Saying "the salt was compromised" doesn't make sense, since there's no "one" salt, and it doesn't need to be "compromised", since it's stored in the clear along with each hash.
- deleted 12y ago[deleted]
- ketralnis 12y agoSince nobody has said it yet... don't salt or hash your passwords, and don't parrot the line "salt your hashes" because it's a massive oversimplification and the easy/naive way is wrong. Hashes, cryptographic hashes included, are designed to be fast. Unfortunately, that means that they're also fast to brute force. Use bcrypt[1] or a proper key derivation function[2] like PBKDF2[3] [1] http://en.wikipedia.org/wiki/Bcrypt http://en.wikipedia.org/wiki/Bcrypt [2] http://en.wikipedia.org/wiki/Key_derivation_function http://en.wikipedia.org/wiki/Key_derivation_function [3] http://en.wikipedia.org/wiki/PBKDF2 http://en.wikipedia.org/wiki/PBKDF2