Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Django uses a salted hash - each password is stored with a random hash code unique to that password, e.g.:

sha1$0ae33$b8a9502237851f302170e1bb207d4eb3f36d9a31

The 0ae33 is different for each stored password, and is used as part of the SHA1 hash. This means you have to brute force each account separately - you can't just use a pre-generated SHA1 lookup table.

It sounds like you know your stuff though - if there's anything we could do to make this secure (while not depending on any libraries other than the Python standard library) please share!



That's still not secure, because SHA1 is very fast. To get "secure" from that, you need to iterate the function several thousand times, or use bcrypt.


Or use scrypt, which is far more secure than bcrypt. :-)


Do you have a website or blog entry which explains in detail why using bcrypt is more secure than hash+salt, and how one is supposed to properly store passwords with crypt? Is it because Blowfish is more computationally expensive, and if so, how by how much compared to SHA-1? How does it compare to using larger hashes such as SHA-512 and Whirlpool? Why Blowfish instead of AES?




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: