Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 18 Dec 2012 09:34:15 +0400
From: Solar Designer <>
Subject: Re: Intentionally Increasing Collisions in Password Hashing Algorithms

On Mon, Dec 17, 2012 at 12:19:40AM -0500, Matt Weir wrote:
> Hash Type: vBulletin (version 3.8.5)
> Justification: This hash is A) weak, B) widely used, and C) salted.
> Ideally we should be focusing on getting people to at least upgrade to
> phpass before we start mucking around with hash collisions, but I
> wanted to look at a really weak hash first.

Why look at a really weak hash first?  I think it only makes sense to
consider controversial changes such as deliberate hash collisions on top
of state of the art setups.  So you should assume that it takes between
1 ms and 100 ms to validate a password on one CPU core, and that
cracking speed is almost the same (no advantage from GPUs either) -
e.g., you may use 1000 c/s (corresponds to latency of ~10 ms on a
multi-core server).

I recall that you had proposed those deliberate hash collisions for web
app default settings (assuming that those are relatively low value
accounts).  If so, the web app is supposed to at least use bcrypt first,
before we consider adding controversial things like this.


Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.