#amoebaOS

Connecting...
Say Hello ▶
subject: Problem with Beta CodePosted: 8:50pm, Feb 14, 2011
offline
2586 posts
Is there an algorithm for your codes, or do you just make them up based on your specific stuff....
(Dont know if that makes sense figuring its SHA1)





funstuff234, amoebaOS Moderator. Check out my amoebaOS blog at http://amoebaos.blogspot.com/
emailpm
subject: Problem with Beta CodePosted: 2:23am, Feb 15, 2011
offline
197 posts
wanted to unhash my beta code with brute force
but i gave up because my email is super long





emailpm
subject: Problem with Beta CodePosted: 1:40pm, Feb 15, 2011
offline
3772 posts
I heard it's impossible to unhash md5...






noname
emailpm
subject: Problem with Beta CodePosted: 7:50pm, Feb 15, 2011
offline
197 posts

Quote: tonynoname

I heard it's impossible to unhash md5...

i said brute force...it means the computer generates all possible combinations and hash it, then compare with inputted hash code


emailpm
subject: Problem with Beta CodePosted: 8:05pm, Feb 15, 2011
offline
3772 posts
It takes a while though right?






noname
emailpm
subject: Problem with Beta CodePosted: 8:18am, Feb 16, 2011
offline
197 posts

Quote: tonynoname

It takes a while though right?

yea. especially with long stuffs like my email (28 chars)


emailpm
subject: Problem with Beta CodePosted: 12:54pm, Feb 16, 2011
offline
4343 posts

Quote: funstuff234

Is there an algorithm for your codes, or do you just make them up based on your specific stuff....
(Dont know if that makes sense figuring its SHA1)
You guys are pretty interested in this, eh?  : P

The codes are generated by hashing a string containing a number of variables. Even with the assumption of brute-force attacks being attempted on the codes, they are still extremely secure - even if someone cracked the code, that code is one-time-use and linked to the email address it was sent to. If the person who received that code had already signed up, cracking it does nothing. Even with the insight you would gain from cracking the code, it would also be impossible to generate new ones, because the API for doing so is behind authentication, unpublished and undocumented.

To put it plainly, cracking a beta code is probably the single most difficult way to gain access to amoebaOS. In reality, I am certainly the weak point in this chain, and a little bit of social engineering would get anyone the beta code they need pretty easily.


It's not impossible to "unhash" MD5 (decrypt or decipher would be a better term). Actually, it's extremely fast compared to most other cryptographic algorithms, because MD5 was designed for speed, not security. amoebaOS will begin migrating to Blowfish encrypted passwords soon, which will be much more secure.
__________________________________________
- Jason || developer amoebaOS @ developIT
emailpmEdited 1 time.Last Edit: 12:55pm, Wednesday February 16, 2011
subject: Problem with Beta CodePosted: 1:40pm, Feb 16, 2011
offline
3772 posts
Blowfish? That sounds like windows 95, what's it like?






noname
emailpm
subject: Problem with Beta CodePosted: 2:06pm, Feb 16, 2011
offline
4343 posts
Blowfish is a cryptographic hash algorithm.



__________________________________________
- Jason || developer amoebaOS @ developIT
emailpm
subject: Problem with Beta CodePosted: 8:12pm, Feb 16, 2011
offline
3772 posts
Hmm, in that case someone would have to social engineer. Which is very hard to do with me...






noname
emailpm
There are 43 posts in this topic.
Currently Reading:
Powered byCommunitY