Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Xk
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
121.
▲
by
Xk
16y ago
What? No. Not at all. The most number times a given salt||hash occurs in the database is seven. Why do you think that what you said is true?
122.
▲
by
Xk
16y ago
I'm not sure what you mean by 'default salt'. In the gawker leak, the first two characters of the stored hash were not a default salt, they were random salts. As for how they're generate? Well, randomly.
123.
▲
by
Xk
16y ago
Then we agree. Had other holes not been there, the fact that sV39Fw5at18zo occurs seven times probably indicates it is a common password. I would even guess it was '123456', or one of the other top four passwords. In reality though, seven a
124.
▲
by
Xk
16y ago
It wasn't the 7-bit salts that let the crackers get access to the passwords. It was DES crypt that did. They could have used 1024 bit salts and the passwords would have been cracked just as quickly. I just ran a quick shell script over the
125.
▲
by
Xk
16y ago
I guess he could mean that you could find a plaintext that had the same hash value through use of a collision ... but that's just finding a preimage.
126.
▲
by
Xk
16y ago
Wrong. Collisions can be found in MD5 in 2^21 time due to an attack by Xie and Feng. 2^64 is a very respectable number and is not practical for people to do on their home machines. 2^21 is.
127.
▲
by
Xk
16y ago
You are correct: 2^10 - 2^5 != 2^(10-5); which is what he is doing by subtracting the entropy.
128.
▲
by
Xk
16y ago
Yeah, that's entirely possible. I guess my argument made the assumption the government would know what it was doing.
129.
▲
by
Xk
16y ago
But what doesn't make sense is that they would sign him on with an NDA that expired, knowing full well that he could then go on and tell people that the FBI had put a backdoor in something they helped to design.
130.
▲
by
Xk
16y ago
> My NDA with the FBI has recently expired [...] Sorry, but that kind of ends it for me. Either the FBI was so ignorant they had him sign an NDA which they knew would expire, and then told him to put in backdoors; or he's lying.
131.
▲
by
Xk
16y ago
(Aside: I'm sure that tptacek could give a significantly better answer here than I can, but I'll give it a shot. (And then whenever he answers trust him more than me.)) Assume you have a perfect cryptographic hash function H(X). No matter h
132.
▲
by
Xk
16y ago
I would imagine some kind of zero-knowledge proof would work here, but that would require more server interaction than just doing the hashes in the first place.
133.
▲
by
Xk
16y ago
If you have ten people logging in per second, you've got to have more than one server. Distribute the login requests. And if it really kills you to make it take a full second , then make it take 1/10th of a second: there, now your hashing
134.
▲
by
Xk
16y ago
If you're talking about why you don't do hash.update(salt) on every round, well it turns out that H(salt || H(H(H(H(H(H(password))))))) is just as strong as H(salt || H(salt || H(salt || H(salt || H(salt || H(salt || H(salt || password)))))
135.
▲
by
Xk
16y ago
Yes there is. A hash function does protect a user's password. If you don't believe me, consider this hash function H(A) = (A>>1)&0xFFFFFFFF There. Hash function. It sends any input to a 32 bit value. Would you use it for your pa
136.
▲
by
Xk
16y ago
Yeah, by "doesn't apply" I meant "that's not very useful for password hashes".
137.
▲
by
Xk
16y ago
Ah, alright. I was thinking there was some kind of length-extension weakness (which doesn't apply here, which is why I was confused) or some other attack in the cryptographic sense. Thanks.
138.
▲
by
Xk
16y ago
I'm curious what the attack is that makes that easier to crack than the Gawker way. (I'm sure you're right, I just didn't know that it would be easier.)
139.
▲
by
Xk
16y ago
What do you mean by "my salting algorithm is very strong"?
140.
▲
by
Xk
16y ago
> And with GPUs rainbow tables are gone Not exactly. I could have a rainbow table for every possible password eight characters or fewer, and find it in a rainbow table in log(table_size) but to brute force it might take several days. GP
141.
▲
by
Xk
16y ago
> they impose a heavy performance penalty on authentication to avoid a relatively rare case You're authenticating over the internet . What is 1/10th of a second to authenticate the first time you want to log in relative to everything e
142.
▲
by
Xk
16y ago
No, I'm not trying to argue that at all. That case is entirely the rapist's fault. The difference I am trying to make is people have trusted (maybe wrongly) Gawker to protect their information. Gawker failed to do so.
143.
▲
by
Xk
16y ago
Yeah, I am. I'm looking at the database right now. I would assume they had more, faster computers. And the passwords they broke were only the simple ones -- I would assume your password is not password1.
144.
▲
by
Xk
16y ago
True. But this article was about Bcrypt, so I'm writing that instead of Scrypt. Edit: I defer to tptacek.
145.
▲
by
Xk
16y ago
Bcrypt has been around for ten years. No one has broken it yet. Is this perfect? No. But then again, we don't know that the implementation you would pick for MD5, SHA1, etc are perfect either. You take the best you can get.
146.
▲
by
Xk
16y ago
SHA512 is very, very fast compared to Bcrypt. It's only slightly slower than SHA1 or SHA256. Source: http://www.cryptopp.com/benchmarks.html
147.
▲
by
Xk
16y ago
I am not disagreeing. I believe these crackers should serve jail time just as much as you do. I am just stating that I do not lift blame from Gawkers.
148.
▲
by
Xk
16y ago
No. No no no. The source code to the hashing algorithm means nothing . It is already open source! The reason that the salt is there is to prevent against rainbow tables. The salting did NOT become useless. If they had not salted passwords,
149.
▲
by
Xk
16y ago
No. Use Bcrypt. Always. Bcrypt is backed by Blowfish, designed by Bruce Schneier. Go look it/him up. It's secure. MD5/SHA1/etc are not weak because they are cryptographically weak (though some are), it is weak because they are fast. SHA3,
150.
▲
by
Xk
16y ago
That's a nice metaphore, but I think it is wrong wrong at a very critical level. If these crackers had went after a single user and decided to trash his webpage, release his emails, and ruin his life, then yes, I would agree with you -- the
More ›