Re: md5 collision generator - Mailing list pgsql-admin

From Matthew D. Fuller
Subject Re: md5 collision generator
Date
Msg-id 20051116174309.GK20846@over-yonder.net
Whole thread Raw
In response to Re: md5 collision generator  (Tom Lane <tgl@sss.pgh.pa.us>)
Responses Re: md5 collision generator  (Joe Conway <mail@joeconway.com>)
List pgsql-admin
On Wed, Nov 16, 2005 at 10:29:09AM -0500 I heard the voice of
Tom Lane, and lo! it spake thus:
>
> The existence of this algorithm is disturbing, since it implies that
> MD5 is weaker than people thought,

It occurs to me that, controlling everything that would be poking into
that part of the database, it would be possible to store the password
with several DIFFERENT hash algorithms, which would save us in the
future from any of them being easily crackable (or even ALL of them,
unless you can somehow create a collision across them all
simultaneously).  It seems that even with 2 or 3 weak hashes, that
might be safer long-term than with just 1 strong hash.  I s'pose it
would add a little cost to the connection-establishing process...


--
Matthew Fuller     (MF4839)   |  fullermd@over-yonder.net
Systems/Network Administrator |  http://www.over-yonder.net/~fullermd/
           On the Internet, nobody can hear you scream.

pgsql-admin by date:

Previous
From: Bruno Wolff III
Date:
Subject: Re: md5 collision generator
Next
From: Joe Conway
Date:
Subject: Re: md5 collision generator