He said he was using SHA1 which to me is not an implication. Is SHA1(k.nonce,password) not a form of SHA1? All you had to do was say, with the information available, you would not have been able to determine the…
Actually I thought I paraphrased it pretty well but to I guess a direct quote is better. "The config salt isn't present in my post -- I'm assuming a database breach, like that which usually occurs. The digest does…
Jmilikin already stated the config salt is not present, that the password IS 4 ASCII digits and he assumes a database breach. Isn't it up to the attacker to figure out the rest of the details? As an attacker, do you…
He said he was using SHA1 which to me is not an implication. Is SHA1(k.nonce,password) not a form of SHA1? All you had to do was say, with the information available, you would not have been able to determine the…
Actually I thought I paraphrased it pretty well but to I guess a direct quote is better. "The config salt isn't present in my post -- I'm assuming a database breach, like that which usually occurs. The digest does…
Jmilikin already stated the config salt is not present, that the password IS 4 ASCII digits and he assumes a database breach. Isn't it up to the attacker to figure out the rest of the details? As an attacker, do you…