464
submitted 3 months ago* (last edited 3 months ago) by qaz@lemmy.world to c/mildlyinfuriating@lemmy.world

Just take the string as bytes and hash it ffs

you are viewing a single comment's thread
view the rest of the comments
[-] CommanderCloon@lemmy.ml 6 points 3 months ago

Because then that means you don't salt your hashes, or that you distribute your salt to the browser for the hash. That's bad.

[-] frezik@midwest.social 4 points 3 months ago

You could salt it. Distributing a unique salt doesn't help attackers much. Salt is for preventing precomputing attacks against a whole database. Attacking one password hash when you know the salt is still infeasible.

It's one of those things in security where there's no particular reason to give your attacker information, but if you've otherwise done your job, it won't be a big deal if they do.

You don't hash in the browser because it doesn't help anything.

[-] FierySpectre@lemmy.world 1 points 3 months ago

It helps against the server being able to read the password, so a bad actor (either the website itself or after a hack) could read your password. Which isn't bad if you're using good password hygiene with random passwords, but that sadly is not the norm.

[-] frezik@midwest.social 2 points 3 months ago

It doesn't. It just means the attacker can send the hash instead of the password.

[-] FierySpectre@lemmy.world 1 points 3 months ago* (last edited 3 months ago)

For that particular website yes, but a salted client side hash is worthless on a different website.

Edit: plus even unsalted it would only work if the algorithm is the same and less iterations are done

[-] frezik@midwest.social 2 points 3 months ago

If the end user is reusing passwords. Which, granted, a lot of people do.

On the flip side, we're also forcing the use of JavaScript on the client just to handle passwords. Meanwhile, the attack we're protecting against only works for reused passwords, and the attacker is inside the server and can see the password after transport layer encryption is removed. This is a pretty marginal reason to force the complexity of JavaScript.

this post was submitted on 26 Aug 2024
464 points (95.5% liked)

Mildly Infuriating

35455 readers
258 users here now

Home to all things "Mildly Infuriating" Not infuriating, not enraging. Mildly Infuriating. All posts should reflect that.

I want my day mildly ruined, not completely ruined. Please remember to refrain from reposting old content. If you post a post from reddit it is good practice to include a link and credit the OP. I'm not about stealing content!

It's just good to get something in this website for casual viewing whilst refreshing original content is added overtime.


Rules:

1. Be Respectful


Refrain from using harmful language pertaining to a protected characteristic: e.g. race, gender, sexuality, disability or religion.

Refrain from being argumentative when responding or commenting to posts/replies. Personal attacks are not welcome here.

...


2. No Illegal Content


Content that violates the law. Any post/comment found to be in breach of common law will be removed and given to the authorities if required.

That means: -No promoting violence/threats against any individuals

-No CSA content or Revenge Porn

-No sharing private/personal information (Doxxing)

...


3. No Spam


Posting the same post, no matter the intent is against the rules.

-If you have posted content, please refrain from re-posting said content within this community.

-Do not spam posts with intent to harass, annoy, bully, advertise, scam or harm this community.

-No posting Scams/Advertisements/Phishing Links/IP Grabbers

-No Bots, Bots will be banned from the community.

...


4. No Porn/ExplicitContent


-Do not post explicit content. Lemmy.World is not the instance for NSFW content.

-Do not post Gore or Shock Content.

...


5. No Enciting Harassment,Brigading, Doxxing or Witch Hunts


-Do not Brigade other Communities

-No calls to action against other communities/users within Lemmy or outside of Lemmy.

-No Witch Hunts against users/communities.

-No content that harasses members within or outside of the community.

...


6. NSFW should be behind NSFW tags.


-Content that is NSFW should be behind NSFW tags.

-Content that might be distressing should be kept behind NSFW tags.

...


7. Content should match the theme of this community.


-Content should be Mildly infuriating.

-At this time we permit content that is infuriating until an infuriating community is made available.

...


8. Reposting of Reddit content is permitted, try to credit the OC.


-Please consider crediting the OC when reposting content. A name of the user or a link to the original post is sufficient.

...

...


Also check out:

Partnered Communities:

1.Lemmy Review

2.Lemmy Be Wholesome

3.Lemmy Shitpost

4.No Stupid Questions

5.You Should Know

6.Credible Defense


Reach out to LillianVS for inclusion on the sidebar.

All communities included on the sidebar are to be made in compliance with the instance rules.

founded 1 year ago
MODERATORS