MD5 for password hashes

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Mike Jackson wrote:

> Richard Megginson wrote:
>
>> Del wrote:
>>
>>> Rich Megginson wrote:
>>>
>>>> We hope to have another binary release by the end of the week.  
>>>> We've just got a couple of bug fixes to go.
>>>
>>>
>>>
>>>
>>> Hi Rich,
>>>
>>> <prod>!
>>>
>>> http://directory.fedora.redhat.com/wiki/Download has pointers to new
>>> releases (Fedora Directory Server 1.0) but the links all give me 404's.
>>>
>>> So are we getting closer to that binary release?
>>
>>
>>
>> Closer . . .
>
>
> You do realize that MD5 has been _fully_ broken now, don't you? And 
> I'm not talking about dictionary attacks; I'm talking about a fast 
> mathematical attack vector on the algorithm itself.
>
>
> An interesting demonstration here:
>
> http://www.doxpara.com/?q=node&from=10
>
>
> Collision generators here:
>
> http://www.stachliu.com/collisions.html
>
> The new and improved collision generator:
>
> http://www.stachliu.com/md5coll.c
>
> "Old (Wang, et al.) average run time on IBM P690 supercomputer - 1 hour"
>     - out of reach for most people
>
> "New average run time on P4 1.6ghz PC - 45 minutes"
>     - within reach for nearly everyone
>
>
> Now, storing md5 doesn't seem much safer than storing crypt.

That's why cert based auth is the best way to go.  But in the meantime, 
the next release of FDS will support SHA-256, SHA-384, and SHA-512 
password hashing.

>
> -- 
> mike
>
> -- 
> Fedora-directory-users mailing list
> Fedora-directory-users at redhat.com
> https://www.redhat.com/mailman/listinfo/fedora-directory-users

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3312 bytes
Desc: S/MIME Cryptographic Signature
Url : http://lists.fedoraproject.org/pipermail/389-users/attachments/20051116/188f838a/attachment.bin 


[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux