* Nick Hilliard via db-wg
> Gert Doering wrote on 10/04/2019 11:08:
>> The attack vector against unsalted hashes is "rainbow tables"... make the
>> API key something like 80 characters long, and no machine in the world
>> can do anything but brute force.
> 
> which will work until the DB ends up on https://haveibeenpwned.com/

Guys,

JFYI - https://lirportal.ripe.net/api/ already exists and the API keys it
issues can apparently be used to maintain your RPKI data.

It doesn't seem to me like adding the possibility for database maintenance
via an API key make things any worse from a security standpoint.

Tore

Reply via email to