Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Sat, 22 Aug 2015 05:07:39 +0300
From: Solar Designer <solar@...nwall.com>
To: john-dev@...ts.openwall.com
Subject: Re: The cmp_all() of cq

On Sat, Aug 22, 2015 at 09:48:08AM +0800, Kai Zhao wrote:
> On Sat, Aug 22, 2015 at 9:16 AM, Solar Designer <solar@...nwall.com> wrote:
> > I am surprised you haven't found more false positives at just that
> > cmp_all() level.
> 
> I think I did not find more false positives because the wrong passwords
> are those:
> 
> 31337313
> 31337313
> 31337313
> 31337313
> 31337313
> 
> or
> 
> 80808080\200""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""
> 80808080\200####################################################################################################################
> 80808080\200$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
> 80808080\200%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
> 80808080\200&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&
> 80808080\200''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
> 
> The wrong passwords are really rarely used.

I think you didn't find more false positives not because these wrong
passwords are rarely used (this shouldn't matter for the likelihood of
false positives), but rather because there are so few of them.

Alexander

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.