Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Given 10^6 possible first names (that's really generous but, hey, I like my dictionaries to be cosmopolitan in character) and 10^6 domains (again, generous) exhaustive search takes 10^12 hashes. My laptop can do 10^7 in a second. This means you have about 10^5 seconds until your email is broken given that the MD5 hash is divulged. That's plus or minus three hours.

Your call on whether "An adversary can only defeat my security given three hours and a hardware investment of $1,600 2010 dollars" is an acceptable security bound for your users. If it isn't, don't use MD5 for crypto purposes.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: