note 86067 deleted from function.md5 by danbrown

From: Date: Mon, 20 Jun 2011 15:21:05 +0000
Subject: note 86067 deleted from function.md5 by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-180744@lists.php.net to get a copy of this message
Note Submitter: stevish at gmail dot com ---- This is partly in response to postfix at bk dot ru, concerning rainbow tables and the security of md5 as a password hash. The idea behind rainbow tables is to, over time, create a database that contains all the possible md5 hashes. They don't need to contain every possible *password* because if they find a 3 letter word that produces the same hash (known as a "collision") as your 46 digit, alpha-numeric password that includes english, russian, and japanese characters... they can just use the 3 digit one instead. Now I'm not certain, but I think that with regular md5 hashes (unsalted) there is already a complete rainbow table in existence. This is why salts are useful. Adding a salt to the password before hashing it forces attackers to create a brand new rainbow table, because the existing ones are useless. And if you go a step further with a script that uses a different salt for each user, they can only crack one password at a time. And speaking of time... that is another important factor. The quicker a computer is able to hash a password, the more passwords it can try per second. A simple md5, for instance, can be calculated several hundred times per second on an average server. If, however, your script hashes the password 2,000 times, it will take a brute force attack at least 5 seconds per password (which means it would take roughly 33,109 years to run every 8 digit password using only lower case letters). So... straight md5 = practically plain-text to a determined attacker. Unique salts, and more server intensive hashes = a long life of boredom to a determined attacker.

« previous php.notes (#180744) next »