其實呢, 如果popvote programming 班友係醒既, 佢可以係client side 先RSA (or other asymmetric key encryption schemes) 個HKID 同電話號碼再hash. 另一方法係用random salt. 但如果佢地真係醒既, 佢地做左都唔會話你知。
另外, 我對 "15,445M c/s" 係完全無興趣。我地擔心既係個 architecture 夠唔夠secure。一個好既implementation 對呢D所謂 "15,445,000,000M c/s" 其實無大影響。
"The cracking tools are not cracking the hash. They are comparing the hashes instead." 呢方面同意, 因為係Point #2 我都有陳述。
"One thing that I should mention is that the HKID card numbers and telephone numbers are not hashed and they are stored in the database in plain text from the captioned hack."
個hacker 講啫, 無人知係唔係真係621 popvote d 資料。如果條友真係好似佢所講咁清高, 佢就唔會放左個似是而非既 encrypted 7zip 出黎。仲有, 呢個世界有D野叫做honeypot. 如果popvote真係implemented 佢所講既野, 理論係無可能有plaintext 資料係server。出現呢D笑料, 一係hacker講大話或真心膠, 一係 popvote講大話。呢一刻無人知。
"if the data is hashed with salt and transmitted via SSL, the data still can be cracked if the hacker can access the database. The key is time and money. With the help of oclhashcat, the time will be reduced a lot if working with suitable hardware. "
我係細果時都好迷戀"速度"呢樣野。但當你大過你就會明白, 黑白兩方係平手既。另如好真係好似你咁講到D algorithm, implementation 等 係咁脆弱,我諗你應該要仲驚過我, 因為最少起碼你EPC dollar 多過我.
"Cracking tools are comparing the hashes instead of cracking the hash, you should keep in mind about that."
唉, 本如想完, 但最終又要回帶 - 呢方面同意, 因為係Point #2 我都有陳述。
"If the web application uses SHA-256 as hash algorithm, the web application will response very slowly and it will looking like hang when it is busy. "
不解釋: http://www.cryptopp.com/benchmarks.html
學下computer architecture. 學下 programming. 用人地寫出黎既野同自己親手做, 所學到既野同成就感係唔同嫁。其實我年紀係唔細, 所以有時係會長氣D。希望你地呢D後生既, 後浪推前浪 |