Re: [cryptography] Adobe confirms customer data breach

2012-11-22 Thread Solar Designer
On Mon, Nov 19, 2012 at 02:19:22AM -0500, Jeffrey Walton wrote: Has anyone come across a paper on how to migrate an existing database with, for example, unsalted MD5 hashes, to something more appropriate for 2012? Naively, I don't see why MD5(password) cannot be an input to an improved system.

Re: [cryptography] Adobe confirms customer data breach

2012-11-19 Thread Peter Gutmann
Jeffrey Walton noloa...@gmail.com writes: I'm trying to figure out why folks like Adobe (who know better and have the resources) are still using unsalted MD5. It's Adobe, you don't even need to go after their passwords, just convince an employee there to click on a PDF attachment or view a Flash

Re: [cryptography] Adobe confirms customer data breach

2012-11-19 Thread Jeffrey Walton
Hi Ian, On Mon, Nov 19, 2012 at 5:24 AM, ianG i...@iang.org wrote: On 19/11/12 18:19 PM, Jeffrey Walton wrote: An Adobe break in does not surprise me. Has anyone come across a paper on how to migrate an existing database with, for example, unsalted MD5 hashes, to something more appropriate