Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Salted md5 is still surely laughably weak in an age of GPU cracking?


Sure. I guess there's not a whole lot of excuses to avoid bcrypt these days.

Bozo's idea was to show that unsalted MD5 is, for most passwords, as bad as no encryption at all. An attack doesn't get much easier than a lookup table.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: