3 ms·
quick answer - It's probably computationally infeasable to gain access to any specific account, or all accounts in the database. It's probably feasible to gain
by Yen 12y ago
quick answer - It's probably computationally infeasable to gain access to any specific account, or all accounts in the database. It's probably feasible to gain access to at least one account in the database, if it has a weak password.
Hashing functions like bcrypt are intentionally set up to be computationally expensive, so that when brute-forcing a password, attackers can only try, say, 1 thousand passwords per second, not 10 million, on any given computational unit. The exact numbers of attempts-per-second depends on the attacker's computer, and the exact setup of their password hashing.
When trying to find the password for a particular hash, which is a hash of a strong password, there's really no better way than trying all possible passwords, hashing them, and seeing if they match.
When attacking a whole database at once, sometimes you get lucky and some accounts have weak passwords, and those you crack quickly.
- deleted 12y ago[deleted]