Hacker Newsnew | past | comments | ask | show | jobs | submit | DevopsTux's commentslogin


Because no hash is eternal and it is only a matter of time between it being leaked and it being cracked. How long depends on a lot of stuff (technology, implementation, password quality and, overall, the value of the account).

Salting, specifically only has one function: making rainbow tables useless and difficulting hash analisys, it is the deffinition of buying you time and making the attacker think twice by requiring more resources (ideally enough that it;s not worth trying)

So, if you know that your users creds are compromised, the only logical answer is to reset them. What you did when hashing is buying time. The difference is that if you bought enough there is little change of incidents from the leak. If you didn't it may get messy. And will.


https://blackhat.guru/short/JpgkES

   > http://127.0.0.1:22342/2/life%20of%20pi%20audiobook%20CHAPTER%2065%20FULL%5Bfreemp3q.org%5D.flv
oh, it sounds like an audiobook abouth mathematics, interesting


Not so much math. Life of Pi was a 2001 novel about the son of a zoo manager and his life after being shipwrecked with a Tiger.

It was made into a 2011 movie, that had a home release in 2012, which no doubt also had a anti-piracy campaign by the studio around the same time as the movie and home release.


i think it was a joke...


Oh, it may have been. Wouldn't the first time I hear "woosh".


I wonder, if I installed Google desktop on an old PC image and stored "life of pi audiobook CHAPTER 65 FULL[freemp3q.org].flv" in "htdocs/2/", would it still be found? Are these delistings just empty promises? :-)


There is only one way to find out. Don't leave us hanging


Welp, they have been using devs Google search history to send them some coding challenges + and an interview for a position there for a long while now. (and probably other unspeakable things, who knows)

If your search history matches the developer profile they put together with your data you get abducted and dropped here https://foobar.withgoogle.com/ . Scary.

https://www.freecodecamp.org/news/the-foobar-challenge-googl...


The amount of data that is sent during the unlock process is absolutely ridiculous. Ever had an environment variable you don't want to share with Xiaomi, together with IP address, mail, phone number, geolocation, serial numbers, etc. ? Because all these gets sent. Unnecessary.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: