A forum I belong to has been hacked, including personal info as well as
passwords.

How do they use this information?

I presume they try the hash function on all combinations of possible
passwords.  (Naturally optimized for faster convergence).  They see a
match, i.e. a letter combination resulting in the given hash of the
password.

If they crack one password, does that make cracking the rest any easier?

And does "salt" simply increase the difficulty, and indeed can it be
deduced, as above, by cracking a single password?

.. or is it all quite different from this!

   -- Owen
============================================================
FRIAM Applied Complexity Group listserv
Meets Fridays 9a-11:30 at cafe at St. John's College
to unsubscribe http://redfish.com/mailman/listinfo/friam_redfish.com

Reply via email to