Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's going to vastly increase the number of attempts required though, which may be sufficient to make it practically impossible, no?


Increase number of attempts? Yes. Practically impossible? Not in the slightest.


What I was thinking was that if the brute-force took 2 weeks (say) and the randomisation added just a single order of increase it could be sufficient to make the crack no longer worthwhile (eg passwords are changed monthly) - ie impossible in a timely manner which achieves the aims of the cracker.

It is not that it is impossible technically , it is that it is no longer possible to use the crack to good effect [ie "practically"].

Do you still disagree - I thought it was a truism that increasing attempts meant the crack could become impractical.


It's a timing attack remember, not an ordinary brute force. The randomization adds almost no extra time.

You only have to calculate the random average once, and you anyway need to collect lots of timing data.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: