Re: PEAR Auth, File_Passwd, and crypt() limitation?

From: Date: Tue, 19 Apr 2005 03:57:02 +0000
Subject: Re: PEAR Auth, File_Passwd, and crypt() limitation?
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-37275@lists.php.net to get a copy of this message
Tomas V.V.Cox wrote:
2^64 key space for MD5 2^80 key space for SHA1 DES is publically accepted as an insecure crypt algo, MD5 could be reduced to 2^32 and the SHA1 recent discoveries looks to lower its key space to 2^69.
These are birthday attacks, that if I'm not mistaken don't apply here. Birthday attack requires attacker generated ciphertext (or part of it), which, if we're talking about passwords, doesn't seem too useful. --- Ants

« previous php.pear.dev (#37275) next »