Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sordidarray
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
sordidarray
16y ago
Godel's Incompleteness Theorems are probably some of--if not the most---misunderstood concepts in all of mathematics (rivaling Cantor's Uncountability Theorem). While the usual analogy for the first theorem is drawn to the liar's paradox ("
2.
▲
by
sordidarray
17y ago
Currently such attacks are infeasible, but there are some very interesting, and very promising families of collision-based attacks (such as herding) which may yield results in that area, although such attacks may only work in specific cases
3.
▲
by
sordidarray
17y ago
Yes, that's why I specifically said, "in current use." No one should be using SHA-3 hash functions. SHA-256 and SHA-1 are much slower than MD5 and very much slower than MD4. The "Getting much better" comment was in reference to speed improv
4.
▲
by
sordidarray
17y ago
Of course I'm not suggesting such a thing. The effort required to implement bcrypt in new systems is indeed small, and such a method is the suggested way to do, but depending on the amount of users, the effort required to port an existing d
5.
▲
by
sordidarray
17y ago
I'm not "arguing for the sake of arguing." I'm trying to explain my point to you, and I'm doing so in a polite manner, which is exactly what I'd expect from you. The weaknesses in SHA-1 make it a poor cryptographic hash, which make it a poo
6.
▲
by
sordidarray
17y ago
I never said SHA-1, a cryptographically insecure hash, was a good choice. It's important to note in your differences that, for the most part, cryptographic hash functions in current use have gotten much slower (e.g., SHA-256 vs MD5), but ar
7.
▲
by
sordidarray
17y ago
I'm not talking about a different problem. The bruteforce attack described in the article primarily affects short and dictionary-based passwords. If the password is of sufficient length and complexity (the keyspace is large enough), then br
8.
▲
by
sordidarray
17y ago
A poorly-written web app whose SQL database is compromised has bigger problems than protecting the integrity of poorly chosen passwords (especially if they store financial information). Losing such a collection of salted hashes does not ren
9.
▲
by
sordidarray
17y ago
I disagree wholeheartedly. The article is based around the fallacy we've seen time and time again, of throwing more cryptography at a problem that cryptography alone cannot solve. In the end, a crappy password is a crappy password. Successf
10.
▲
by
sordidarray
17y ago
I have a /lot/ of Expos.
11.
▲
by
sordidarray
17y ago
http://calcul.biz/amazon_covers/007054235X.jpg New.
12.
▲
World's most powerful telephoto prime lens on eBay
(cgi.ebay.com)
7 points
by
sordidarray
17y ago
|
1 comments
13.
▲
Godzilla crypto tutorial
(cs.auckland.ac.nz)
1 points
by
sordidarray
17y ago
|
0 comments
14.
▲
by
sordidarray
17y ago
PHP's sigils are superfluous. Perl (from which PHP derives their use) utilizes sigils with respect to typing in order to denote scalar variables ($), arrays (@) and hashes (%). What does PHP use the $ sigil for? Everything but references (&