<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Google as a password cracker</title>
	<atom:link href="http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/</link>
	<description>Security Research, Computer Laboratory, University of Cambridge</description>
	<pubDate>Mon, 12 May 2008 00:53:49 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: michosn</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-29109</link>
		<dc:creator>michosn</dc:creator>
		<pubDate>Wed, 30 Apr 2008 11:52:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-29109</guid>
		<description>i found many sites that give md5 coding and decoding like
http://www.joomlaaa.com/md5-coding-decoding
i do not know how they can decode md5
anyone know a script to decode md5</description>
		<content:encoded><![CDATA[<p>i found many sites that give md5 coding and decoding like<br />
<a href="http://www.joomlaaa.com/md5-coding-decoding" rel="nofollow">http://www.joomlaaa.com/md5-coding-decoding</a><br />
i do not know how they can decode md5<br />
anyone know a script to decode md5</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Johan Sundström</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-28348</link>
		<dc:creator>Johan Sundström</dc:creator>
		<pubDate>Sat, 01 Mar 2008 19:33:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-28348</guid>
		<description>I just wrapped up a neat web page &lt;a href="http://ecmanaut.blogspot.com/2008/03/google-safing-passwords.html" rel="nofollow"&gt;tool to query Google about MD5, SHA1 and (optionally) plaintext password versions&lt;/a&gt; live. Good fun! :-)</description>
		<content:encoded><![CDATA[<p>I just wrapped up a neat web page <a href="http://ecmanaut.blogspot.com/2008/03/google-safing-passwords.html" rel="nofollow">tool to query Google about MD5, SHA1 and (optionally) plaintext password versions</a> live. Good fun! <img src='http://www.lightbluetouchpaper.org/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: adi</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-27550</link>
		<dc:creator>adi</dc:creator>
		<pubDate>Mon, 07 Jan 2008 12:36:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-27550</guid>
		<description>its a good fun</description>
		<content:encoded><![CDATA[<p>its a good fun</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pr00t</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-27485</link>
		<dc:creator>pr00t</dc:creator>
		<pubDate>Tue, 01 Jan 2008 18:46:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-27485</guid>
		<description>My personnal project:
Online MD5 Reverser - Hash cracker !
http://ice.breaker.free.fr/</description>
		<content:encoded><![CDATA[<p>My personnal project:<br />
Online MD5 Reverser - Hash cracker !<br />
<a href="http://ice.breaker.free.fr/" rel="nofollow">http://ice.breaker.free.fr/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: clic</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-27476</link>
		<dc:creator>clic</dc:creator>
		<pubDate>Sun, 30 Dec 2007 15:34:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-27476</guid>
		<description>with google I have found this:
https://secure.sensepost.com/sp-hash/cigzg

what is?</description>
		<content:encoded><![CDATA[<p>with google I have found this:<br />
<a href="https://secure.sensepost.com/sp-hash/cigzg" rel="nofollow">https://secure.sensepost.com/sp-hash/cigzg</a></p>
<p>what is?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anas</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-27462</link>
		<dc:creator>anas</dc:creator>
		<pubDate>Tue, 25 Dec 2007 22:37:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-27462</guid>
		<description>ok i´ve got a little question , i am from germany btw =)
you are talking all the time about hash etc
do you mean , you coud crak apsses with this?and if yes then HOW ^^ 
greetz</description>
		<content:encoded><![CDATA[<p>ok i´ve got a little question , i am from germany btw =)<br />
you are talking all the time about hash etc<br />
do you mean , you coud crak apsses with this?and if yes then HOW ^^<br />
greetz</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Solomon Haile</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-27439</link>
		<dc:creator>Solomon Haile</dc:creator>
		<pubDate>Tue, 18 Dec 2007 21:15:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-27439</guid>
		<description>very interesting what you can find on google search</description>
		<content:encoded><![CDATA[<p>very interesting what you can find on google search</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jont</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-27423</link>
		<dc:creator>jont</dc:creator>
		<pubDate>Mon, 17 Dec 2007 10:54:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-27423</guid>
		<description>Salt is useful since it forces the off-line password search to be repeated anew for each password you want to break, rather than the attacker being able to use a pre-computed database to attack many passwords in parallel.  And yes, it should be unique per account (or better, per password--new password means new salt).

There's another technique: make the hash algorithm SLOW.  For a simple example, iterate the hash 10,000 times.  The performance impact on your system is negligible, but the performance impact on the attacker is huge.</description>
		<content:encoded><![CDATA[<p>Salt is useful since it forces the off-line password search to be repeated anew for each password you want to break, rather than the attacker being able to use a pre-computed database to attack many passwords in parallel.  And yes, it should be unique per account (or better, per password&#8211;new password means new salt).</p>
<p>There&#8217;s another technique: make the hash algorithm SLOW.  For a simple example, iterate the hash 10,000 times.  The performance impact on your system is negligible, but the performance impact on the attacker is huge.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TC</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-27422</link>
		<dc:creator>TC</dc:creator>
		<pubDate>Mon, 17 Dec 2007 10:13:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-27422</guid>
		<description>@102
We weren't debating which terms we like best. We were debating what are the actual meanings of those terms.

If a person refered to html as a "procedural programming lanaguage", would you tell him that he had that wrong? Or would you say, "Oh, that's the term he prefers, it's just a personal thing, I shouldn't argue the point with him" ?

Anyway - I'm outta here!</description>
		<content:encoded><![CDATA[<p>@102<br />
We weren&#8217;t debating which terms we like best. We were debating what are the actual meanings of those terms.</p>
<p>If a person refered to html as a &#8220;procedural programming lanaguage&#8221;, would you tell him that he had that wrong? Or would you say, &#8220;Oh, that&#8217;s the term he prefers, it&#8217;s just a personal thing, I shouldn&#8217;t argue the point with him&#8221; ?</p>
<p>Anyway - I&#8217;m outta here!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SGBotsford</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-27414</link>
		<dc:creator>SGBotsford</dc:creator>
		<pubDate>Sun, 16 Dec 2007 07:37:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-27414</guid>
		<description>@Mark:
   Ok, why would unsalted vs salted be a divisor of logN

In terms of collisions: If MD5 is a random hash function (all outputs are equally likely) then adding a salt would not change the time required to get a collision.  It's just that a collision is far less likely to have useful information.

E.g.  You may discover that S1:P1 has the same hash as S2:P2 I don't see how this is a win.</description>
		<content:encoded><![CDATA[<p>@Mark:<br />
   Ok, why would unsalted vs salted be a divisor of logN</p>
<p>In terms of collisions: If MD5 is a random hash function (all outputs are equally likely) then adding a salt would not change the time required to get a collision.  It&#8217;s just that a collision is far less likely to have useful information.</p>
<p>E.g.  You may discover that S1:P1 has the same hash as S2:P2 I don&#8217;t see how this is a win.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
