Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
timo_h
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
Show HN: Procedural Music Workstation in the Browser
(manager.kiekko.pro)
9 points
by
timo_h
7mo ago
|
0 comments
2.
▲
by
timo_h
3y ago
The same principle applies to SHA-512 just the same (much cheaper to attack non-stretched SHA-512 hash than attacking directly the bcrypt hash). There are both MD5 hashes and SHA-512 hashes lying around, which makes "hash shucking"
3.
▲
by
timo_h
3y ago
> When using bcrypt, make sure to use the following algorithm to prevent the leading NULL byte problem. and the 72-character password limit: > bcrypt(base64(sha-512(password))) Pre-hashing the password, in this context, without a salt
4.
▲
by
timo_h
5y ago
Firefox is great on desktop, been my primary browser for 15+ years. Sadly though, the mobile version (still) lacks support for "pull to refresh" gesture. Other than that, mobile FF is great (privacy features, browser addons...).
5.
▲
Acceleration Attacks on PBKDF2: Or, What Is inside the Black-Box of OclHashcat?
(usenix.org)
2 points
by
timo_h
10y ago
|
0 comments
6.
▲
by
timo_h
11y ago
This was probably the most notorious misuse of scrypt. Memory usage of scrypt was tuned to take 128KB, which made Litecoin mining ~10 times faster on GPUs than on CPUs.
7.
▲
by
timo_h
12y ago
Some of this is good advice, but there's a BIG point on the 'Password Storage Cheatsheet' that's linked and referenced by the above article, that I don't think is solid. I read they recommend to use the both (adap
8.
▲
Prince – Modern password guessing algorithm [pdf]
(hashcat.net)
58 points
by
timo_h
12y ago
|
5 comments
9.
▲
Is infosec a game?
(openwall.com)
2 points
by
timo_h
12y ago
|
0 comments
10.
▲
A fast, Cross-VM attack on AES [pdf]
(eprint.iacr.org)
28 points
by
timo_h
12y ago
|
11 comments
11.
▲
PHP Data Encryption Primer
(timoh6.github.io)
3 points
by
timo_h
12y ago
|
0 comments
12.
▲
by
timo_h
13y ago
Before the Breaker 101 course starts, I invite you to take a quick (15 questions) quiz about web application security practices and quirks: http://timoh6.github.io/WebAppSecQuiz/index.html
13.
▲
Web App Sec Quiz: 15 questions about security quirks related to web app dev
(timoh6.github.io)
1 points
by
timo_h
13y ago
|
0 comments
14.
▲
by
timo_h
14y ago
> That's defending against a newly generated rainbow table. You lost me here. Anyway, the attacker does not need a rainbow table at all to attack against multiple hashes at the price of one. > That's repeating the first point with d
15.
▲
by
timo_h
14y ago
> I don't understand how salts could help against timing attacks, though. The salt which is unknown/unpredictable (and contains enough entropy) to the attacker makes his offline attack against the hash unfeasible (after he has managed
16.
▲
by
timo_h
14y ago
At least, testing passwords against multiple hashes (at the price of one) is impossible. And it is not possible to see if different entries shares a same password (or to see if they have a different password). Also, it (probably unintention
17.
▲
by
timo_h
14y ago
> But salts don't have to be strictly unique, they only have to be a barrier to rainbow tables. Rainbow tables are not the only "attack vector" that proper use of salts defeats.
18.
▲
GenPhrase - Easy to memorize random passphrase generator for PHP applications
(github.com)
1 points
by
timo_h
14y ago
|
0 comments
19.
▲
TCrypto - Simple and flexible PHP 5.3+ key-value storage library
(github.com)
2 points
by
timo_h
14y ago
|
0 comments