User Tag List

Page 2 of 2 FirstFirst 1 2
Results 11 to 18 of 18

Thread: MD5 Object?

  1. #11
    Clicker Fusion 2.5 Developer

    Join Date
    Jun 2006
    Posts
    414
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Re: MD5 Object?

    Well, don't feel too secure storing just the MD5 of your passwords. It's a good pratice, but it is possible to get the password from the MD5 by brute force attack, for which programs are not uncommonly avaliable.

    That said, it will at least make anyone who retrieved the password MD5s(which shouldn't happen to begin with) work to get the actual passwords. So lazy people will be stopped. hehe ^_^

  2. #12
    Clicker Fusion 2.5 Developer

    Join Date
    Jun 2006
    Posts
    414
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Re: MD5 Object?

    Well, don't feel too secure storing just the MD5 of your passwords. It's a good pratice, but it is possible to get the password from the MD5 by brute force attack, for which programs are not uncommonly avaliable.

    That said, it will at least make anyone who retrieved the password MD5s(which shouldn't happen to begin with) work to get the actual passwords. So lazy people will be stopped. hehe ^_^

  3. #13
    No Products Registered

    Join Date
    Jun 2006
    Posts
    9
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Re: MD5 Object?

    You make it sound like a simple and typical attack that joe hacker uses every day. Brute forcing MD5 is not easy or fast and when you are done you have a string that generates the same signature as the original password which is very different than having the password.

  4. #14
    No Products Registered

    Join Date
    Jun 2006
    Posts
    9
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Re: MD5 Object?

    You make it sound like a simple and typical attack that joe hacker uses every day. Brute forcing MD5 is not easy or fast and when you are done you have a string that generates the same signature as the original password which is very different than having the password.

  5. #15
    No Products Registered

    Join Date
    Jul 2006
    Posts
    63
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Re: MD5 Object?

    " but it is possible to get the password from the MD5 by brute force attack"

    This is irrelevant - its not a flaw in the md5 algorithm, its just possible with anything. You can brute force anything, does not mean it will get you anywhere.

    Brute forcing a 10 character password with md5 will take around 20+ years to do on a home computer (8 characters would take something like 8 hours, so theres a considerable difference).

    If your really worried about security, add a salt to the string before you generate the md5sum so the user's password choice (even a single character) would be incredibly difficult for the brute force method.

  6. #16
    No Products Registered

    Join Date
    Jul 2006
    Posts
    63
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Re: MD5 Object?

    " but it is possible to get the password from the MD5 by brute force attack"

    This is irrelevant - its not a flaw in the md5 algorithm, its just possible with anything. You can brute force anything, does not mean it will get you anywhere.

    Brute forcing a 10 character password with md5 will take around 20+ years to do on a home computer (8 characters would take something like 8 hours, so theres a considerable difference).

    If your really worried about security, add a salt to the string before you generate the md5sum so the user's password choice (even a single character) would be incredibly difficult for the brute force method.

  7. #17
    Clicker Fusion 2.5 DeveloperAndroid Export Module

    Join Date
    Jun 2006
    Location
    Melbourne, Australia
    Posts
    765
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Re: MD5 Object?

    Hmmm you could brew your own with the LUA object as a suggestion.

  8. #18
    Clicker Fusion 2.5 DeveloperAndroid Export Module

    Join Date
    Jun 2006
    Location
    Melbourne, Australia
    Posts
    765
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Re: MD5 Object?

    Hmmm you could brew your own with the LUA object as a suggestion.

Page 2 of 2 FirstFirst 1 2

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •