[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

Is it a good idea to create relatively simple passwords for websites

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 10
Thread images: 2

File: sha256.png (2KB, 160x144px) Image search: [Google]
sha256.png
2KB, 160x144px
Is it a good idea to create relatively simple passwords for websites and use SHA-256 to hash them?
>>
No, use bcrypt you fucking mong.
>>
>>61303551
Why don't you use a hashing algorithm actually made for password hashing like bcrypt?
>>
>>61303570
>>61303571
To clarify, this is what they are talking about: https://security.stackexchange.com/a/6415
>>
Just treat pass "words" as random binary blobs. Use GRC secure passwords to generate one set of 64 random printable characters for every website and use whatever password manager you like to remember them.

Keep in mind many sites are stupid enough to have a maximum password length limit. You're gonna have headaches with the simple method outlined above, let's not even consider SHA-256.
>>
>>61303655
I think he's talking about making up easy passwords and then using SHA-256 to generate a huge string to serve as the password from the site's point of view.

I seriously doubt he's writing his own authentication solution. If he is then he should strongly consider killing himself instead.
>>
File: Ghyi9nL.jpg (40KB, 540x960px) Image search: [Google]
Ghyi9nL.jpg
40KB, 540x960px
>using a technique that takes 100ms to check the passwords

Enjoy your DoS, losers...
>>
>>61305121
>5 wrong attempts
>locked out for 5 minutes
>lock out period increases exponentially
>>
>>61303551
No, because hashing does not increase the entropy of the passwords.
>>
>>61305440
This is ill-advised; if you lock out, they switch to using DDoS and switch locked resources to a different IP. The correct approach when a flood is detected is to silently flag the IP's (or invalidate session tokens in some cases) to fail the checks as inexpensive and normal-seeming as possible for the duration of the "lockout," whose timer resets on any attempt.
Thread posts: 10
Thread images: 2


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.