November 11th, 2011, 13:43
Posts: 3,781
Threads: 26
Joined: Sep 2010
Mardoc Wrote:If you'd rather have mine - they're two levels of security. A hash is a function that's chosen to be easy to calculate forwards and hard to go backwards.
So something like prime factorisation then?
Travelling on a mote of dust, suspended in a sunbeam.
November 11th, 2011, 14:39
Posts: 6,487
Threads: 63
Joined: Sep 2006
Ok, I knew what hashing was but salting was new. Where does the input data to be added to the password to make it 'salted' come from?
November 11th, 2011, 14:41
Posts: 2,261
Threads: 58
Joined: Oct 2010
Mardoc Wrote:Here's one explanation
If you'd rather have mine - they're two levels of security. A hash is a function that's chosen to be easy to calculate forwards and hard to go backwards. It's used by never actually storing a password; instead, every time a site would use a password, they compute the hash of it and use that instead. This is why sites can usually reset your password but can't usually just tell you what your old password was.
However, now that computing power is cheap, people found a way around hashing - they build a dictionary of hashes for all common passwords, and compare the hashes they steal to that dictionary to get the passwords. Salting is adding one more step - after you take the password from the user, you add some more data (the 'salt'), unique to the user, and hash the combination of them. This means that that dictionary for cracking has to be recreated for each user instead of for each site, and has to be a lot bigger.
Edit: Another explanation, with numbers and examples: Here
Very interesting and useful for me, thanks for posting.
November 11th, 2011, 14:46
Posts: 7,766
Threads: 94
Joined: Oct 2009
sunrise089 Wrote:Ok, I knew what hashing was but salting was new. Where does the input data to be added to the password to make it 'salted' come from?
It's just a random number. It gets stored alongside the hashed+salted password, and even though the attacker can see it, it still serves its purpose: they can't use a pre-computed lookup table of hashes of common passwords.
November 12th, 2011, 01:04
(This post was last modified: November 12th, 2011, 01:35 by antisocialmunky.)
Posts: 4,443
Threads: 45
Joined: Nov 2009
You also can't as easily guess the hashing algorithm.
As for salt, imagine the classic Caesar cypher where you encode letter by shifting the alphabet by 1 A->B B->C C->D ... Z->A. Salt would be like an additional value used in some way (most commonly added to the ascii representation) so for a Caesar cypher it would be something like shifting each word in the message over a few letters like:
helloxyou (use x instead of space
Shifted over 2 would be:
lohelxouy
Then encoded:
mpifmypvz 2
Additionally as hashes often discard some information (unlike a caesar cypher), you can't decode the encoded version, you have to guess a message, salt and hash it. So you can't just look up 'helloxyou' in a table of for caesar cypher shift right 1 due to the salt value.
In Soviet Russia, Civilization Micros You!
"Right, as the world goes, is only in question between equals in power, while the strong do what they can and the weak suffer what they must."
“I have never understood why it is "greed" to want to keep the money you have earned but not greed to want to take somebody else's money.”
November 12th, 2011, 02:05
Posts: 875
Threads: 3
Joined: Mar 2011
As in all things, use different passwords for things you care about. So you don't have to go and find all 20 different accounts that used the same SN/Password combo and change them.
I personally have a standard throwaway one, but for important stuff (Google, Steam, Money stuff, etc) keep unique strong passwords.
November 12th, 2011, 11:15
Posts: 4,443
Threads: 45
Joined: Nov 2009
Keepass is a good tool for keeping track of a ton of different passwords, it even has a browser plugin.
http://keepass.info/
In Soviet Russia, Civilization Micros You!
"Right, as the world goes, is only in question between equals in power, while the strong do what they can and the weak suffer what they must."
“I have never understood why it is "greed" to want to keep the money you have earned but not greed to want to take somebody else's money.”
November 14th, 2011, 03:08
Posts: 3,918
Threads: 14
Joined: Feb 2011
I don't think our PBEM passwords are encrypted at all
November 14th, 2011, 03:10
Posts: 2,521
Threads: 26
Joined: Oct 2010
Nicolae Carpathia Wrote:I don't think our PBEM passwords are encrypted at all data:image/s3,"s3://crabby-images/3df58/3df5857df63f2158f60fda5c2886035be69e594b" alt="lol lol" Actually, you're wrong. They are md5 hashed inside the save files. This makes them either trivial or nearly impossible to break depending on password length and composition.
November 14th, 2011, 04:20
Posts: 2,257
Threads: 13
Joined: Jun 2010
Can you explain md5 hashed, mist?
|