Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
heliosyne
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
heliosyne
2y ago
I didn't complain about anyone. The Okta vulnerability isn't because of public salts.
2.
▲
by
heliosyne
2y ago
No, rainbow tables are hash-input specific. They're user-specific only if the salt is user-unique. Usernames aren't normally part of the hash input because they're assumed-public knowledge. You can test this for yourself by
3.
▲
by
heliosyne
2y ago
Because bcrypt is still viable. Its cost factor is easily scaled to commodity performance, keeping the attack cost high. The main attack vector these days is GPU-based compute. There, SHA* algorithms are particularly weak because they can
4.
▲
by
heliosyne
2y ago
The security of salting is twofold. Yes, it defeats the common rainbow table. But if the salt is known, a rainbow table for that salt can be computed. The security of salting depends on the salt being unknown. If the salt is externally kno
5.
▲
by
heliosyne
2y ago
Desktop and phone: Firefox + uBlock. Router is OPNsense with its own validating recursor, domain blacklist, and routing blackhole. Phone runs a private VPN to my router when not on my home network.