in reply to Re^3: SaltedDigest Salt?
in thread SaltedDigest Salt?
prevent them from compromising all the accounts quickly
No, it prevents them from quickly finding accounts with weak passwords
certainly does not prevent them from targeting selected accounts. If the have both the hash and the salt, it becomes a matter of cpu cycles, and with AWS and other selling those so cheaply, it is just a matter of how much they are prepared to spend.
Oh, really? Could you estimate how much it will cost to crack 16 characters random alphanumeric password (let's assume we're using SHA512)? And how many CPUs do I need if I want it this life? Maybe CPU cycles not exactly the right thing in this case.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^5: SaltedDigest Salt?
by BrowserUk (Patriarch) on Feb 08, 2012 at 18:45 UTC | |
by zwon (Abbot) on Feb 09, 2012 at 02:27 UTC | |
by BrowserUk (Patriarch) on Feb 09, 2012 at 04:32 UTC | |
by zwon (Abbot) on Feb 09, 2012 at 13:27 UTC | |
by BrowserUk (Patriarch) on Feb 09, 2012 at 18:22 UTC | |
|