Cronwerks MCCode/MCCodes Forums

Please login or register.

Login with username, password and session length

News:

Can't find exactly what you've been wanting? Try searching for what you are looking for in the search box to the right. ----------->


This forum is now closed and has moved to a new location! Click here to find out why.

Poll

What type of encryption

MD5
SHA1
SHA1 encrypted with username
Other, ive posted it in the topic
Pages: [1] 2 3

AuthorTopic: Password Security  (Read 2414 times)

Danny696

  • Senior Member
  • ****
  • Reputation Power: 317
  • Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.
  • Offline Offline
  • Posts: 540
    • View Profile
    • WWW
Password Security
« on: December 18, 2009, 05:21:19 PM »
Well, as most of you will know, MD5 just isnt secure enought now-a-days, Im thinking we should SHA1 it, mabey even a a salt, like SMF does with their username. Watta you think.
Logged
Project Choosen - 10%
Daniel - Hanson . Com

Danny696

  • Senior Member
  • ****
  • Reputation Power: 317
  • Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.
  • Offline Offline
  • Posts: 540
    • View Profile
    • WWW
Re: Password Security
« Reply #1 on: December 18, 2009, 05:22:28 PM »
Poll added.
Logged
Project Choosen - 10%
Daniel - Hanson . Com

Zeddicus

  • Basic Member
  • *
  • Reputation Power: 0
  • Zeddicus is looked down upon.Zeddicus is looked down upon.
  • Offline Offline
  • Posts: 42
    • View Profile
    • WWW
Re: Password Security
« Reply #2 on: December 18, 2009, 06:09:13 PM »
I use "sha512" with a salt, sha1() will soon be just as bad as md5.
Logged

JoshuaDams

  • Active Member
  • **
  • Reputation Power: 129
  • JoshuaDams is working their way up.JoshuaDams is working their way up.JoshuaDams is working their way up.
  • Offline Offline
  • Posts: 240
    • MSN Messenger - immortalthug4ever@hotmail.com
    • View Profile
    • WWW
Re: Password Security
« Reply #3 on: February 07, 2010, 05:03:56 AM »
sha512 with salt was my suggestion (:

Spudinski

  • Basic Member
  • *
  • Reputation Power: 42
  • Spudinski has no influence.
  • Offline Offline
  • Posts: 53
  • I have cookies!
    • View Profile
    • WWW
    • Email
Re: Password Security
« Reply #4 on: February 07, 2010, 05:20:38 AM »
It really doesn't matter what encryption I use, I just like to focus on my actual website and database security.
If I make my website fort knox, how are they going to be able to see any password anyways.

But I prefer to salt my hashes as well, but using something a little different, the average oak would never think about.
I use a timestamps as salts, and just make a insert to the database with the password, and update the time stamp as well - this is just so brute-force attacks will take allot longer.

But these days, even I sit with the power of knowing about 2.5mil hashes in their "decrypted" form - so nothing is really going to help you regarding encrypting the passwords, rather secure your website.
Logged
If you see a post that just doesn't just seem right, send me a PM.
Offering services for small-type games and websites, send me a PM if you want/need something done.

Danny696

  • Senior Member
  • ****
  • Reputation Power: 317
  • Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.
  • Offline Offline
  • Posts: 540
    • View Profile
    • WWW
Re: Password Security
« Reply #5 on: February 07, 2010, 06:09:01 AM »
im thinking about whirlpool, not been decrypeted yet
Logged
Project Choosen - 10%
Daniel - Hanson . Com

Zeddicus

  • Basic Member
  • *
  • Reputation Power: 0
  • Zeddicus is looked down upon.Zeddicus is looked down upon.
  • Offline Offline
  • Posts: 42
    • View Profile
    • WWW
Re: Password Security
« Reply #6 on: February 07, 2010, 06:49:45 AM »
Quote
sha512 with salt was my suggestion (:

Look when I posted lol, you posted your 'encryption' technique 10 days *after* I said that.

I only posted mine without salt as it's not needed atm. (You know where.).
Logged

JoshuaDams

  • Active Member
  • **
  • Reputation Power: 129
  • JoshuaDams is working their way up.JoshuaDams is working their way up.JoshuaDams is working their way up.
  • Offline Offline
  • Posts: 240
    • MSN Messenger - immortalthug4ever@hotmail.com
    • View Profile
    • WWW
Re: Password Security
« Reply #7 on: February 07, 2010, 01:31:19 PM »
LOL this is the first time i've actually even bothered to browse through this section of the boards >,<

You posted your sha bit somewhere?

Spudinski

  • Basic Member
  • *
  • Reputation Power: 42
  • Spudinski has no influence.
  • Offline Offline
  • Posts: 53
  • I have cookies!
    • View Profile
    • WWW
    • Email
Re: Password Security
« Reply #8 on: February 07, 2010, 01:39:48 PM »
@danny - well, whirlpool is just another encryption, I'd suggest you don't use it, it's basically just a longer string than sha and md so it just uses more database space.

Also, the term and actually also the word decrypt doesn't exist, it's just a term that people use now days. All they do is compare the hash.
Logged
If you see a post that just doesn't just seem right, send me a PM.
Offering services for small-type games and websites, send me a PM if you want/need something done.

CrimGame.com

  • Basic Member
  • *
  • Reputation Power: 21
  • CrimGame.com has no influence.
  • Offline Offline
  • Posts: 42
  • Play with me baby!
    • View Profile
    • WWW
Re: Password Security
« Reply #9 on: February 10, 2010, 02:42:50 AM »
whirlpool is just longer... You are a expert?


This was tested with 1024000 bytes (1000 KB) of random data

Results: (in microseconds)
whirlpool - 64682.96
md5 - 6890.058
sha1 - 8886.098
sha384 - 45102.119
sha512 - 45655.965
Source php.net

It maybe longer but the fact of it using

Whirlpool: 3bff3f475277fd87357cd4d2fc97a134af5efe570910d21f
1185e391f78f7d4b7c33a0a289efe1632b2026d77074ff50
7691c24c9782c5cce654dd01ea446a15

MD5: e6bdf8faab4a42ab37e3e833641dfe90

SHA1: abe7076758e0937c13743d26f9323897b57cb4dc

SHA384: bb7b69c28c09d42212ec83ed40e2b3454233c72fd2c268c2
fbcce477312d65e4fb36382235bc3febadde73660ffbeb4a

SHA512: a5179ffb67450eb83f8cdd915ee8c3037bb4d87f7e677311
819d5fb3dafaf54ac4c55405c7997adad8df3d6615964dda
5aa67acf27ea4c62e1d40f049b531d81

Different hashes ain't "just longer strings", Whirlpool is one hash i've always wanted to explore and considering you say it will use more space then i wouldn't want to be on your hosting.

Maybe do a little research into encryptions/hashes and you'll work out they ain't "just longer strings".
« Last Edit: February 10, 2010, 02:45:05 AM by zero-affect »
Logged

Spudinski

  • Basic Member
  • *
  • Reputation Power: 42
  • Spudinski has no influence.
  • Offline Offline
  • Posts: 53
  • I have cookies!
    • View Profile
    • WWW
    • Email
Re: Password Security
« Reply #10 on: February 11, 2010, 08:07:14 AM »
Thanks for pointing out they use different encryption methods, eh?
Still, it doesn't matter what you encrypt "CrimGame.com " with, it can still be revealed by comparison.
Logged
If you see a post that just doesn't just seem right, send me a PM.
Offering services for small-type games and websites, send me a PM if you want/need something done.

CrimGame.com

  • Basic Member
  • *
  • Reputation Power: 21
  • CrimGame.com has no influence.
  • Offline Offline
  • Posts: 42
  • Play with me baby!
    • View Profile
    • WWW
Re: Password Security
« Reply #11 on: February 11, 2010, 11:15:43 PM »
find me 5 whirlpool comparison websites... think not
i could find 5 md5 comparison websites within seconds...

Whirlpool looks bigger so people will avoid it, it is bigger but shown in my previous post it loads data faster than md5 and sha1.

So Spud are you just stupid or do i have to basically spell it out for you, md5 is slower than whirlpool and it's been compared on so many websites, whirlpool is rarely compared and is faster.

The logically one to use would be whirlpool (even if it's "longer"), i mean come on it's obvious why even try and defend your plainly "blond moment" statement.

Djkanna

  • Basic Member
  • *
  • Reputation Power: 0
  • Djkanna is looked down upon.
  • Offline Offline
  • Posts: 29
    • View Profile
Re: Password Security
« Reply #12 on: February 13, 2010, 02:11:01 PM »
Hehe CrimGame :P

I use sha512 (no no-one told me too... Although I did get and idea of how to use random salts with it from someone else)

Use what you like that way if something should happen to go wrong you can only blame yourself :)
Logged

Spudinski

  • Basic Member
  • *
  • Reputation Power: 42
  • Spudinski has no influence.
  • Offline Offline
  • Posts: 53
  • I have cookies!
    • View Profile
    • WWW
    • Email
Re: Password Security
« Reply #13 on: February 13, 2010, 06:06:28 PM »
I've had it until here whit you Crim to be real honest with you, I don't see the point in arguing with someone with such minimal knowledge of security.

I guess you also expect Google to render you those pages of FBI's most top secret documents on the web too, eh?
No, I but I could find you a thousand websites that does comparisons that includes whirlpool, but I don't have the time to waste on minimalistic things, as you surely can - I'm sure you probably already did a Google search for it, eh?

Well, also, point 0.0000002 of a second really isn't going to matter as much as the space it will use in my database, since you began to drag out the analytics parts of this, I will too.
I'm not going to argue with you when you have truly NO knowledge about large scaled systems, and how they process data. But here is a tip for you, you keep running on that shared host of yours that gets - maybe, if even - 2k unique visits a month, and then leave the real "stuff" to the people who actually knows what the hell they are talking about.
Logged
If you see a post that just doesn't just seem right, send me a PM.
Offering services for small-type games and websites, send me a PM if you want/need something done.

Cronus

  • Administrator
  • Senior Member
  • *****
  • Reputation Power: 2901
  • Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!
  • Offline Offline
  • Posts: 550
    • MSN Messenger - preston__08@hotmail.com
    • View Profile
    • WWW
Re: Password Security
« Reply #14 on: February 13, 2010, 09:35:23 PM »
Topic Unlocked.

You can't simply get frustrated and lock topics because you think someone isn't "qualified" enough to have a part in the conversation. All parties involved need to calm down and discuss, without throwing punches. This is being DISCUSSED, not fought over.
Logged
My msn is preston__08@hotmail.com if anyone is interested, I am online frequently.
Pages: [1] 2 3
« previous next »
 


This forum is now closed and has moved to a new location! Click here to find out why.