in reply to (ichimunki) Re: Too Convenient Security? (updated)
in thread Too Convenient Security?
ichimunki wrote:
So maybe I don't have the advanced math skillz to comprehend this, but when I produce an MD5 hash from an input (salt or no) I don't get a string such as the one you indicate.
Using Digest::MD5 will not generate a string like that. See the link that mdillon referred to for a better explanation of how that string is created.
ichimunki also wrote:
Finally, remember this all comes down to the passwords. Are they computationally inconvenient? If not, I might simply use LWP to keep submitting until I find a match. Your CGI should prevent weak passwords. And as part of defense in depth I would (as I said) limit the number of invalid tries.
Without going too in-depth into our password policies, let me just say two things:
Cheers,
Ovid
Join the Perlmonks Setiathome Group or just click on the the link and check out our stats.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: (Ovid)Re: (ichimunki) Re: Too Convenient Security?
by thraxil (Prior) on Jan 08, 2002 at 03:23 UTC | |
by cforde (Monk) on Jan 09, 2002 at 02:37 UTC | |
by jepri (Parson) on Jan 09, 2002 at 16:31 UTC |