Using Google To Crack MD5 Passwords
stern writes "A security researcher at Cambridge was trying to figure out the password used by somebody who had hacked his Web site. He tried running a dictionary through the encryption hash function; no dice. Then he pasted the hacker's encrypted password into Google, and voila — there was his answer. Conclusion? Use no password that any other human being has ever used, or is ever likely to use, for any purpose. I think."
No, the conclusion is you should always use salted hashes.
He could have discovered this if he had used a database complete with names, something I don't think would have been too difficult for him.
This Google search idea is kind of moot if the user uses some very basic password construction such as what I've commented on before. Also, as the blog mentions, this discussion is worthless if WordPress used salting which is related to nonces used in security engineering. I think that stuff has been around for, what about five years now? Wake up WordPress!
My work here is dung.
In Soviet Amerika, MD5 passwords crack you.
Most MD5 password hashes, such as those used in *nix, are salted, and hence secure from this sort of vulnerability. That Wordpress uses unsalted MD5 sums to store passwords boggles my mind. It shows that the developers know even less about cryptography than I do. That's scary.
My blog
The password was hunter2?
The grass is always greener on the other side of the light cone.
You're correct. You have totally invalidated the points I brought up in my post. Good show.
I looked these up on google, and they directed me to some slashdot page...