Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×
Encryption

John the Ripper Cracks Slow Hashes On GPU 61

solardiz writes "A new community-enhanced version of John the Ripper adds support for GPUs via CUDA and OpenCL, currently focusing on slow-to-compute hashes and ciphers such as Fedora's and Ubuntu's sha512crypt, OpenBSD's bcrypt, encrypted RAR archives, WiFi WPA-PSK. A 5x speedup over AMD FX-8120 CPU per-chip is achieved for sha512crypt on NVIDIA GTX 570, whereas bcrypt barely reaches the CPU's speed on an AMD Radeon HD 7970 (a high-end GPU). This result reaffirms that bcrypt is a better current choice than sha512crypt (let alone sha256crypt) for operating systems, applications, and websites to move to, unless they already use one of these 'slow' hashes and until a newer/future password hashing method such as one based on the sequential memory-hard functions concept is ready to move to. The same John the Ripper release also happens to add support for cracking of many additional and diverse hash types ranging from IBM RACF's as used on mainframes to Russian GOST and to Drupal 7's as used on popular websites — just to give a few examples — as well as support for Mac OS X keychains, KeePass and Password Safe databases, Office 2007/2010 and ODF documents, Firefox/Thunderbird/SeaMonkey master passwords, more RAR archive kinds, WPA-PSK, VNC and SIP authentication, and it makes greater use of AMD Bulldozer's XOP extensions."

Comment Re:Mainstream politicians (Score 1) 1051

"(the right to associate with whom you wish)" -- wrong. It's the right to assemble to petition for the redress of grievances -- the right to protest. Which is speech, not commerce. The constitution *does not* give you the right to associate with whom you wish. If it did, then restraining orders would be unconstitutional, as would judicial orders (as part of their probation, most convicted sex offenders have to stay away from children).

"AND then you abuse the ICC as bad as congress ever did?" - Prohibiting you from turning down a customer on the basis of their race is most certainly commerce. Whether or not it qualifies as interstate depends on the business being regulated.

Comment Re:Mainstream politicians (Score 1) 1051

You're wrong on all counts. Rand Paul said on the night in 2010 when he won the Republican primary that he wants to repeal the civil rights act (because he believes it's unconstitutional for Congress to prohibit businesses from discriminating against black people.)

The first amendment applies to speech and beliefs. It does not apply to your choice of whom to do business with. However, the interstate commerce clause, from which the Civil Rights Act derives its Constitutionality, does.

Comment Re:Four reasons (Score 1) 1264

1) PDF should be used for printing only. Anything else is a misuse of the format.

4) You are flatly wrong if you think all windows software costs money, and the repo system is only better if (a) it actually has what you need and (b) you can figure out how to use it. Otherwise, it's of no use at all.

5) If OSX were like Linux and had 50 different versions each of which required its own set of knowledge and technical skills, that would certainly reduce its usability.

Comment Re:Four reasons (Score 1) 1264

1) I think you missed my point. I wasn't talking about the relative merits of LibreOffice versus MS Office (and frankly, I think you are vastly overstating LibreOffice's merits). I was talking LibreOffice's ability to read and write Microsoft Office documents without error. Document format compatibility with windows is so important that (IMO) anything less than complete fidelity to windows is a failure. Because it means that huge swaths of the marketplace -- pretty much anyone who has to interact with someone else who uses windows -- will avoid using LibreOffice because they can't take the risk that their boss/teacher/co-workers won't be able to read their documents.

3) I haven't used Windows 8, but I'm willing to bet it's trivially easy to enable the start menu. The same cannot be said for disabling Unity and switching to something else.

4) If a user doesn't need to do much more than email, web browsing, and instant messaging, he can probably get everything he needs from the repos. But I'm willing to bet there's a lot of people out there who have at least one app that's not in the repos, or for which the repos have an out-of-date copy (Mediawiki, just to name one) And then Linux becomes a usability disaster.

5) Again, you missed the point. The lack of standardization in everything from package managers (Yum/apt-get) to desktop interfaces (Gnome/KDE/Unity) means that anytime a user encounters a problem and googles it, if he finds an answer at all, there's a pretty good chance that it apply to him because it pertains to a different distro/app. It also substantially increases the learning curve for any newbie and adds artificial barriers for experienced users to switch between distros. And there's no technical reason at all why this should be the case.

Comment Four reasons (Score 4, Informative) 1264

Here's what I think are the five biggest reasons, in roughly descending order of importance:
1) Microsoft Office - like it or not, Microsoft Office is by a huge margin the dominant office suite. You have a presentation to give tomorrow? You better make sure it works on that Windows/Office computer that is connected to the overhead projector. Fuck ups in document formatting/compatibility will not be acceptable. Morale of the story: Until an open source program can read and write Microsoft office documents at damn close to 100% fidelity to their windows counterparts, this will be a HUGE obstacle.
2) Games - Despite repeated predictions of its imminent demise, the PC gaming market should not be underestimated. To some extent, this is a viscous cycle: the Linux community ignores the potential increase in market share from gamers, and software companies ignore the Linux market (because it's too small to be economically viable).
3) Poor UI choices - Unity. Enough said.
4) Package installation/management - Let's say a hypothetical windows-to-linux convert wants to install a program. If he's using a distro that uses apt/yum, and if what he wants to install is available in the repositories, and if the distro is configured to use those repositories by default, then he's in pretty good shape. If any of these conditions doesn't hold, then our user is screwed. This is one area where Windows is light years ahead of Linux. If you get a Windows installer and run it, it installs with a minimum of hassle, and you'll never ever be told that your compiler is out-of-date or to use certain compiliation flags or to manually install a dozen dependencies.
5) Lack of standardization in configuration - It is not helpful to google a problem and get eight different answers depending on which distro you use. Like the poor UI choices, this is largely a self-inflicted wound.

Comment Re:Hey guys, STFU and build a rocket, would you? (Score 1) 616

"And by that time, we will have economically feasible solutions."

(1) You're ignoring the positive feedback mechanisms that make global warming so dangerous. A small increase in world temperature (which we're already experiences) tends to lead to decrease glaical cover, decreasing the earth's albedo and creasing the solar enrgy absored by the earth. It also warms the oceans, and causes them to release CO2. These in turn trigger more warming. So a little bit of prevention today tends to be much cheaper than dealing with it tomorrow.

(B) Your "solution" is essentially that we sit back and pray that some magic bullet comes down the pike. That's unrealistic in the extreme.

Comment Re:Hey guys, STFU and build a rocket, would you? (Score 2) 616

Let's go for the long hanging fruit first. How about we stop pumping/mining carbon based energy sources from the ground and burning them into the atmosphere. I bet that would drastically reduce the among of greenhouse gases released. (And would have the nice side effect of being sustainable and cheaper in the long run)

Comment Re:If It Is Fact ... (Score 5, Insightful) 616

"it only takes one person with a cogent argument to disprove something." -- Wrong. It takes empirical evidence, not a cogent argument. The consensus view that the earth is getting warmer is backed by literally hundreds of published papers each of which cite physical evidence, measurement, models, etc. If there was a case to be made that the consensus view is wrong, there would have to be *some* evidence out there somewhere that contradicts the consensus view. There is not, and that' is why there are no papers describing it.

Comment Re:Hey guys, STFU and build a rocket, would you? (Score 5, Informative) 616

"There are way worse greenhouse gasses that don't even get filtered most of the time. Cause actually carbon dioxide isn't all that strong of a greenhouse gas."

This is an example of a little knowledge being a dangerous thing. What you said it true, but basically irrelevant. Carbon dioxide might not be the worst greenhouse gas, but (A) we release orders of magnitude more of it than any other green house gas. You could eliminate every methane emitter on earth and not make a dent in global warming because well over 90% of it comes from the CO2 we release. (B) Carbon dioxide-caused warming lasts far longer than any other green house gas. If we stopped emitting CO2 tomorrow, the warming we have caused will not dissipate for nearly a millenia.

Comment Re:If It Is Fact ... (Score 5, Insightful) 616

"Funny how the chicken little's so easily dismiss all the climate scientists that disagree with the claim that the sky is falling and demonize anyone who attempts to point them out."

What's funny how all those alleged "climate scientists" cited in this letter have yet to publish a single paper that contradicts the consensus view that global warming is real and man-made: "That hypothesis was tested by analyzing 928 abstracts, published in refereed scientific journals between 1993 and 2003, and listed in the ISI database with the keywords “climate change... Of all the papers, 75% fell into the first three categories, either explicitly or implicitly accepting the consensus view; 25% dealt with methods or paleoclimate, taking no position on current anthropogenic climate change. Remarkably, none of the papers disagreed with the consensus position." -- http://www.sciencemag.org/content/306/5702/1686.full

Comment Re:Completely 100% fine with fracking. (Score 5, Insightful) 267

Won't work. Once they've caused a disaster, they can simply declare bankruptcy. They would either have to put up the money into an escrow account in advance, or purchase insurance against such a possibility. (And greedy bastards that they are, the insurance companies can provide a very useful oversight role in such a role)

On the other hand, it strikes me as a fundamentally radical policy that we are willing to accept the possibility of long-term, effectively unfixable contamination of our underground water sources in exchange for a temporary fix to our energy needs.

Comment Re:Sanity vs. politically motivated scaremongering (Score 1) 267

"Police investigation closed with no support for there having been a hack." - Nice try. Here's a detail of the (competent, non-police) investigation into the hack: http://erratasec.blogspot.com/2009/11/climate-hack-used-open-proxies.html

"None of those eight committees investigated the actual allegations of misconduct found in the mails beyond "did you?". - do you have a citation to prove that? I didn't think so.

Slashdot Top Deals

"Why can't we ever attempt to solve a problem in this country without having a 'War' on it?" -- Rich Thomson, talk.politics.misc

Working...