Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The math doesn't sound right. Google allows any ASCII character for their passwords, which is 95 chars. I calculate 2330 years to crack each password. Did I get something wrong?

(95^6 * .1sec per hash) / (60sec 60min 24hrs 365days)

The key difference is bcrypt does ~10 hash/sec. A GPU-enabled password cracking machine can do over 500 million hashes per second. That generates a rainbow table in ~30 minutes.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: