Menu

#4 case-insensitive hashing insecure?

open
Crypto (1)
5
2009-04-21
2009-04-21
No

Code review shows that the entered password is manipulated in a way that loses its case information for the purposes of hashing the actual pw data. Need to do a bit of research to confirm whether (and to what degree) this is cryptologically significant. This will break existing PW databases, so it should be worked into a major release.

Discussion


Log in to post a comment.