Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sarciszewski
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
sarciszewski
11y ago
That's not very useful for web programmers that are handling their users' passwords, is it?
32.
▲
by
sarciszewski
11y ago
> I believe the Ruby example is incorrect Unfortunately, there's nothing I can do about that, unless someone can point me to an alternative that uses a constant-time comparison. I've left a comment on the pull request so that,
33.
▲
by
sarciszewski
11y ago
That makes a lot more sense. His Facebook profile didn't indicate anything about his background.
34.
▲
by
sarciszewski
11y ago
I feel that this is needlessly dangerous, personally. How are the salts managed? This detail is important. SHA256(scrypt(password, constant_value_instead_of_salt)) is going to produce collisions in the stored hash.
35.
▲
by
sarciszewski
11y ago
How are you going to calculate the scrypt hash, client-side? Doesn't that scrypt hash then become the password, from the server-side application's perspective? How are you storing the salt for the user if your server only knows ab
36.
▲
by
sarciszewski
11y ago
Thanks for the suggestion, I'll put it on the list. :)
37.
▲
by
sarciszewski
11y ago
It would make for a good interactive "chart", perhaps. Whereby, as long as your sliders aren't all the way to the left, the chart is mostly green.
38.
▲
by
sarciszewski
11y ago
The blog post that HN is reading is served by PHP-FPM + nginx, without any extra special features to handle the load of an unexpected "oh hey we made it to the front page of HN". It's also hosted on a relatively cheap VPS.
39.
▲
by
sarciszewski
11y ago
(I'm not ignoring your comment, I'm currently debating whether to update it to include libsodium example code or to write a separate post for that.)
40.
▲
by
sarciszewski
11y ago
I'm part of the Paragon Initiative Enterprises team and have access to edit the blog. If you have any questions (AMA) or would like to suggest any additions, please let me know.
41.
▲
by
sarciszewski
11y ago
> What is more valuable to an attacker? Generally: Being able to deploy malware through a site users trust so you can attack them directly, en masse. But the password hashes are a good runner-up.
42.
▲
by
sarciszewski
11y ago
IANAL but it would probably depend on the GIF itself. Using a particular file format doesn't waive your rights as far as I know.
43.
▲
by
sarciszewski
11y ago
That's the correction. Given that the audience for this blog post is developers, I feel that the current title is precise enough. People who know about password hashing don't need this advice. People who are storing passwords need
44.
▲
by
sarciszewski
11y ago
The title has been corrected as of ~half an hour ago.
45.
▲
by
sarciszewski
11y ago
> I literally don't understand what it is you're getting at. I truly hope this will help then: https://paragonie.com/blog/2015/08/you-wouldnt-base64-a-pass... "Password hashing" is its
46.
▲
by
sarciszewski
11y ago
Okay, thanks for the clarification.
47.
▲
by
sarciszewski
11y ago
I could have sworn it used PBKDF2-SHA256 and Salsa20/8 internally, which is what I meant by "based on".
48.
▲
by
sarciszewski
11y ago
You're right. I've updated the article title to avoid this ambiguity.
49.
▲
by
sarciszewski
11y ago
Correction: Scrypt actually uses PBKDF2 internally. (Previously said "scrypt is based on PBKDF2" but that's a loaded statment.) PBKDF2 is an improvement over PBKDF1 (and other naive iterated hash constructions), but attacks g
50.
▲
by
sarciszewski
11y ago
> For some reason the article completely fails to link to libsodium: https://download.libsodium.org/doc/ The "bindings for most programming languages" link goes to the libsodium documentation, but I'l
51.
▲
by
sarciszewski
11y ago
https://github.com/P-H-C/phc-winner-argon2 is the official repo.
52.
▲
by
sarciszewski
11y ago
> Given BCrypt hashes are a mere 184 bits, I don't see how this is a meaningful concern even in principle. This was added in response to a point that a couple people (or perhaps a convincing sockpuppeteer) raised and tried to use to
53.
▲
by
sarciszewski
11y ago
Precisely what Thomas said. Using == instead of hmac.compare_digest is unlikely to be a source of vulnerabilities in your application, but it's a good habit to get into whenever you touch cryptography. See also: https://news
54.
▲
by
sarciszewski
11y ago
You could potentially leak the first N bytes of a valid unsalted trash hash (e.g. MD5) and then use this information to optimize an offline brute-force attack. The more bytes you leak of the hash, the more you can narrow down your offline a
55.
▲
by
sarciszewski
11y ago
Heh. I might look into dating once I have free time. Currently, I have none. (Also, I'm gay. That might make things much more difficult.)
56.
▲
by
sarciszewski
11y ago
The comment was deleted, but: https://archive.is/QEQPO
57.
▲
Stormpath: Insecure RNGs are “ok with us”
(github.com)
4 points
by
sarciszewski
11y ago
|
3 comments
58.
▲
by
sarciszewski
11y ago
I'm pretty sure I wouldn't survive long on either planet.
59.
▲
by
sarciszewski
11y ago
I'm 26 and I've never even figured out how to start dating. Why are y'all in such a hurry to stop?
60.
▲
by
sarciszewski
11y ago
That's an option for some people, not an option for everyone.
More ›