the whole world burns

Enough With The Rainbow Tables: What You Need To Know About Secure Password Schemes

 # [via]

Short version: of course you need salt, but the real goal is to make brute-forcing infeasible. The best way to accomplish that task is to make your hash function as slow as possible, and able to be slowed even further to compensate for advances in hardware.

AOL’s absurdly bad password system

 #

Issues apparently include:

  • Passwords truncated to the first 8 characters
  • Non-alphanumeric characters stripped
  • Stored encrypted (not hashed) in the Windows registry

And various Unix flavours have similar default behaviour?!

What the devil?

The Whole World Burns is the rephrase miniblog, containing links and other miscellaneous trifles.