|
Message-ID: <20120803180745.GA11936@debian> Date: Fri, 3 Aug 2012 22:07:45 +0400 From: Aleksey Cherepanov <aleksey.4erepanov@...il.com> To: john-users@...ts.openwall.com Subject: Re: any plans to support superlong passwords? On Tue, Jul 31, 2012 at 08:14:32PM -0400, Rich Rumble wrote: > On Tue, Jul 31, 2012 at 6:17 PM, Stephen John Smoogen <smooge@...il.com> wrote: > > What hashes are you talking about? You can get a lot of unlimited > > length hashes via say the --format=crypt which falls back to OS level > > algorithms which are slow but have unlimited lengths. (I do this for > > md5crypt that are longer than 15 characters and similar items). --format=crypt is a good tip. > I've tried some long ones for NT > > "Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do > eiusmod tempor incididunt ut labore et dolore magna aliqua. U > user:025649DF316DAA1842D3CFD2B981158A:::127 characters I think > > "Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do > eiusmod tempor incididunt ut labore et dolore magna aliqua. > user:8778EA7E51275073B11EC595CB8811C1:::space is after the full stop > > "Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do > eiusmod tempor incididunt ut labore et dolore magna aliqua. > user:4F9942C46E4DF4D2351611BE416B76F6:::no space after full stop > > "Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod > user:43940FFADD888E02FC2A00F2B1617457:::74 characters > > The quote for the plain-text above is intention. This is just an > example, it gets tedious to type 20+ character pass phrases so *some* > limits on length isn't all that bad. Team Hashcat said: "... recent breaches. Statistically the average password length is eight (8) characters." (https://contest-2012.korelogic.com/team_hashcat.html ) > I think korelogic stated that the > average password length was 21-22 characters? So perhaps the phrases > we were using could of been more effective during the contest? I could > be wrong. Yes, KoreLogic said about average length of 21 bytes during CMIYC 2012: https://twitter.com/CrackMeIfYouCan/status/229383879063117825 It is possible to have optimized formats without limits. Though I guess it is not worth the effort. Right? Though it is possible to look into reverse way: to add formats with lesser maximum length to achieve higher speeds. Though it seems disputable. Thanks! -- Regards, Aleksey Cherepanov
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.