172
you are viewing a single comment's thread
view the rest of the comments
[-] phoenixz@lemmy.ca -3 points 2 weeks ago

to crack

Eh, sorry, but you cannot crack hashes. At best you can come up with a strong that generates the same hash, but finding the exact original value won't happen, that's not how hashes work, that is not how anything works.

Each hash output value in principle can have an infinity of different inouts that lead to that output. Because of that, hashes are a one way street

Having said that, are you telling me that a properly salted hash using a modern algorithm like argon2id, or just even plain sha256, can be "cracked" in 14 days? I'm going to go ahead and say "no"

[-] Windex007@lemmy.world 7 points 2 weeks ago* (last edited 2 weeks ago)

If you can generate an input which satisfies an md5 comparison which results in being able to authenticate with a system, then I think debating if that is a "crack" or not is purely semantic.

Although you are for sure technically right, I think any actually observed md5 collisions are with very large inputs, many orders of magnitudes longer than a password. The smallest input (first found, almost certainly) is almost certainly what the original password was.

this post was submitted on 08 May 2026
172 points (95.7% liked)

Cybersecurity

10023 readers
153 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 3 years ago
MODERATORS