Programming Theory
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Codewalkers ForumsOther TechnologiesProgramming Theory

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Codewalkers Forums Sponsor:
  #1  
Old September 5th, 2004, 06:17 AM
tkarkkainen's Avatar
tkarkkainen tkarkkainen is offline
Moderator
Codewalkers Regular (2000 - 2499 posts)
 
Join Date: Apr 2007
Location: Finland
Posts: 2,332 tkarkkainen User rank is Lance Corporal (50 - 100 Reputation Level)tkarkkainen User rank is Lance Corporal (50 - 100 Reputation Level)tkarkkainen User rank is Lance Corporal (50 - 100 Reputation Level)  Folding Points: 26229 Folding Title: Starter FolderFolding Points: 26229 Folding Title: Starter Folder
Time spent in forums: 6 Days 16 h 34 m 49 sec
Reputation Power: 5
Can we trust MD5 anymore?

http://eprint.iacr.org/2004/199.pdf

Looks like people can break MD4, MD5, SHA-1 and RIPEMD. I still can't read the language of mathematics well enough so that I could say if that's true or gibberish. People who can, what do you say?

Reply With Quote
  #2  
Old September 5th, 2004, 10:01 AM
Ashkhan Ashkhan is offline
Contributing User
Codewalkers Newbie (0 - 499 posts)
 
Join Date: Apr 2007
Posts: 372 Ashkhan User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 24 m 57 sec
Reputation Power: 3
RE: Can we trust MD5 anymore?

Thanks for pointing this out. This can be a potential threat because so many things depends on MD5 algorithm.

Like this article says it's a time to move to a betterr hash function but there is no need to worry about security of MD5 now.

Reply With Quote
  #3  
Old September 6th, 2004, 12:09 AM
austinb austinb is offline
Codewalkers Newbie (0 - 499 posts)
 
Join Date: Apr 2007
Location: TX
Posts: 59 austinb User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 3
RE: Can we trust MD5 anymore?

Plus there's always the threat of brute-force attacks nomatter what hash you use, in that case its just a matter of computing power.
a md5 hash around 4 letters can take a few minutes, but a hash thats 7 letters can take a few days.
I'd say your best bet is to do a double md5 hash(one hash over the other)
thats way itll look like a 16 bit password that will take a few weeks(unless there are colisions)
make sure u use a salt though, cuz if anyone catches on itll be easy to make a different brute-force prog that double hashes...

the chances that ur md5 is going to be found and that someone think its importaint enough to mess with is low, so i would just stay with plain md5, its always a good idea to use salts to prevent mass dictionary attacks, those can find a password in a few seconds or a few minutes depending on the size of the password.

Reply With Quote
Reply

Viewing: Codewalkers ForumsOther TechnologiesProgramming Theory > Can we trust MD5 anymore?


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump




 Free IT White Papers!
 
Create the Optimal Architecture for your Critical Applications
Warburton's the largest independently owned bakery in the UK faced a number of difficult challenges in providing the most robust yet efficient IT infrastructure for their organization's success. IBM's services combined with their xSeries servers created the perfect platform for their SAP environment with sufficient flexibility, and did so in very time effective fashion.

Request Your Free Technology Downloads!
 
Five Best Practices for Deploying a Successful Service-Oriented Architecture
This white paper describes the benefits you can expect with SOA, and how IBM can help take your business there.

Request Your Free Technology Downloads!
 
Gartner Magic Quadrant for Application Delivery Controllers
Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses of solutions, and provides Magic Quadrant reporting for a quick comparison across all vendors. Learn from Gartner how you can benefit from an all-in-one device like Citrix NetScaler that delivers the highest levels of availability, performance and security.

Request Your Free Technology Downloads!
 
Knowledge is Power
What you don't know can hurt you, and is likely costing you money and increasing your security risks during an era of scarce resources. This white paper proposes six key strategies that enterprise security managers can use to improve their network defense posture.

Request Your Free Technology Downloads!
 
Rationalizing the Multi-Tool Environment
The rationalized multi-tool approach is flexible, scalable and cost effective. It provides the necessary input to the IT service management business processes. It preserves prior investments in monitoring tools, empowers technologists to select the best tools with which to do their jobs, and enhances effective response to incidents.

Request Your Free Technology Downloads!
 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 




© 2003-2010 by Developer Shed. All rights reserved. DS Cluster 4 Hosted by Hostway
For more Enterprise Application Development news, visit eWeek