Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

http://securityledger.com/new-25-gpu-monster-devours-passwor...

25 late 2012 vintage GPUs gets you 180 billion MD5 tries per second. With a fairly modest budget you can rent a whole lot more GPU power than that. A little Googling gets me several companies offering password hash cracking as a service.



> 25 late 2012 vintage GPUs gets you 180 billion MD5 tries per second. With a fairly modest budget you can rent a whole lot more GPU power than that. A little Googling gets me several companies offering password hash cracking as a service.

But we're assuming, at the very least, that they're not using MD5 and are instead using SHA-2/SHA-256 or (s|b)crypt.

There's an order of magnitude difference between brute forcing MD5 and brute forcing something better.


http://hashcat.net/oclhashcat-plus/

MD5 is 2-3x as fast as SHA-1

MD5 is 5-7x as fast as SHA-256

I don't know why anyone would assume they are using anything better than MD5/SHA-1 considering the history of incidents like this.


https://www.livingsocial.com/createpassword: "LivingSocial passwords were hashed with SHA1 using a random 40 byte salt."

Shocker!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: