Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Xk
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
Xk
15y ago
What you describe is basically PBKDF1. If you wanted to make it slightly better, you could go with PBKDF2. It's true that bcrypt is better in some ways, but you're fine with what you're doing now. If you really wanted to improve on things y
32.
▲
by
Xk
15y ago
> The real solution is site security not password security. That does not imply you don't worry about it though -- it's defense in depth. In the same way sometimes you'll need to go through two sets of doors locked with different keys t
33.
▲
by
Xk
15y ago
... what? > Just store in plaintext because I am already assuming you are. No, actually, I don't think I will store plaintext passwords. > All the this talk about sha-1 vs bcrpyt vs scrpyt is nice and all but I have little faith tha
34.
▲
by
Xk
15y ago
When you wrote "this fictional hash" I read that as talking about the SHA-4 I made up, not the one you did. I then didn't respond to the rest of the post because when you said "for password hashing, it's a good start" I again assumed you we
35.
▲
by
Xk
15y ago
(Edit: see child comment -- I was responding to something other than what was intended. I'm leaving this here for clarity, but you can ignore it.) No, not really. Hashing functions aren't designed for passwords, they're mainly used for inte
36.
▲
by
Xk
15y ago
Point taken, it's probably true that the probability that G(F(P)) == G(F(Q)) given F(P) != F(Q) is less than 1 in 2^128. But it's probably also true that it's greater than 0. Clearly it's impossible to be less than zero. So no matter what y
37.
▲
by
Xk
15y ago
SHA-1 is a reasonably good hashing algorithm, but for the sake of argument, I'll talk about an imaginary SHA-4 which is perfect in every respect. It will be a 4096 bit hash function which has no faster-than-bruteforce collisions or preimage
38.
▲
by
Xk
15y ago
Imagine you have two hash functions F and G, both mapping from the domain of integers to integers mod 2^128. Imagine they are perfect in that if you hash all the integers up to some large N, each hash is expected to recorded exactly the sam
39.
▲
by
Xk
15y ago
You have two choices that I see: 1. The next time a user logs in to your system and you verify against the SHA-1 hash that they are who they say they are, recompute the correct hash for bcrypt. Then, delete the SHA-1 hash . It does you no
40.
▲
by
Xk
15y ago
Instapaper stores only salted SHA-1 hashes of passwords, so those are relatively safe. -- Obligatory statement on NEVER USING SHA-1 HASHES to make passwords "safe". Any normal person can brute force millions of SHA-1 hashes (salted howeve
41.
▲
by
Xk
15y ago
This reminds me of Randy Pausch's method of getting someone to sit down for lunch. [1] "And he asked a question. And I was like, I’m sorry did you say you were Tom Furness? And he said yes. I said, then I would love to answer your question,
42.
▲
by
Xk
15y ago
They're both good. I'd pick bcrypt, but if you're using PBKDF2, it's probably because it's simpler to implement.
43.
▲
by
Xk
15y ago
I was describing it in order to explain the general idea; not to explain the exact algorithm. The wikipedia article does a better job at that than I could do, but since he asked the question after the link to the wikipedia article I assumed
44.
▲
by
Xk
15y ago
I assume you know that the reason you add a salt is to prevent rainbow table attacks. Without a salt, if someone obtains the hash then they need to just run it through a single rainbow table and with very high probability, obtain the passwo
45.
▲
by
Xk
15y ago
If you were like me and wondered why they had to go back six after going forward five, it's because they counted wrong. They go forward six and a half turns, and go back six and three quarters.
46.
▲
by
Xk
15y ago
> Its all fun and games until you think May 21st is the date the world will end. ... what? That has nothing to do with number theory. > More seriously, numbers, and number theory, can be quite interesting and often leads to computat
47.
▲
by
Xk
15y ago
[edit: palish deleted his comment; excerpts below for what I was responding to: > Except random numbers aren't random. They only appear to be. If an online casino seeds its random number generator with current time, then you can do the
48.
▲
by
Xk
15y ago
Believe it or not, there are still programs that require blazingly fast bit operations. I used like ten different bit hacks for a game engine I wrote which uses bitboards[1]. [1] http://en.wikipedia.org/wiki/Bitboard
49.
▲
by
Xk
15y ago
One of the ten links on the first page is to a zero-content image intended for humor, and it's from six days ago. The other nine are content: screenshots to prove things, pictures of work environment, etc.
50.
▲
by
Xk
15y ago
Yeah, there are a whole lot of things I could do, but I just wanted a really quick program to see what the relative speeds were. And I have to say I was impressed.
51.
▲
by
Xk
15y ago
That method is, for me at least, really really fast. Eleven seconds to compute the 1,000,000th Fibonacci number. Compared with the naive method which takes 143 seconds. Code below: def add(a, b): return (a[0]+b[0], a[1]+b[1]) def
52.
▲
by
Xk
15y ago
And I could destroy (read: fake transactions, etc) the current banking system given enough computational power. I would start by brute forcing their private keys, and go from there.
53.
▲
by
Xk
15y ago
You should block me from redirecting a link to itself. http://gadaf.fi/5j And probably block cycles too.
54.
▲
by
Xk
15y ago
That's not the reason why people escape quotes. Imagine the case where he had not escaped quotes, but had escaped < and >. In that case, I could put a doublequote/singlequote to break out of the JSON. Then I could just put whatever
55.
▲
by
Xk
15y ago
There's an XSS on the page: Try to login or create an account. Enter this as your username (or password, as long as it's not valid: you need an error), hit submit. Error + XSS. </script><script>alert(1);</script> You
56.
▲
by
Xk
15y ago
It does not treat it as an illegal instruction. It keeps running their code just fine. This is how Imps fight. The most basic imp is defined as mov 0 1 It copies itself to one instruction ahead of itself. On the off chance it hits t
57.
▲
by
Xk
15y ago
We're not freaking out -- we're just curious why things are working the way they are.
58.
▲
by
Xk
15y ago
Maybe it's just switching around randomly for now? Because now I can see the points of both of your comments.
59.
▲
by
Xk
15y ago
It seems that you can still see how many points a comment has when it's nonpositive. Edit: And there are other comments with negative points where the number doesn't show. And still other comments with positive score that are showing up. Co
60.
▲
by
Xk
16y ago
You have an XSS on the login form. I create a page which posts to the login page with the name " onclick="alert('do evil here')" onfocus="alert('do evil here')" foo=" It errors out, and my javascript is now in the input box. They click the
More ›