What's more, if I could do 1 billion MD5s per second, then I could brute force every possible 8 character base-64 password (for one user at a time) in merely 3.25 days. Even if that one user has chosen his or her individual password by pulling it straight from /dev/random. Impractical against a site with 1000 low-value users? Sure, most black hats won't want to spend 5 to 10 years of compute power on that. But that's an utterly practical attack against a single, high-value account. If you're Twitter and someone just stole your salted password hashes, you'd better ring up Ashton Kutcher in the next 24 hours and tell him to change his password right now.
Something truly scary: this level of computer power can be easily achieved today using parallelism. I just now ran a benchmark on my personal Linux machine against 10,000 small files on a ramdisk, each of a size appropriate for salted passwords and each with unique data. According to this benchmark, my Athlon64 running at 800MHz can MD5 100,000 passwords per second using md5sum, complete with the system call overhead of opening and closing ten thousand files. Even so, my machine is only 4 orders of magnitude slower than the monster I described, and one of those orders of magnitude should be written off because my processor is years behind the times (sub-1GHz and single core). Shave off another order of magnitude due to the useless system calls, and one hundred modern $100 commodity processors could do this job today, and you could probably do it for half the price or less if you used DSPs or video card GPUs. This is trivially within the range of a project like Seti@Home or Folding@Home, or a dark-hat version of the same (running on a botnet of stolen CPU cycles).
Addendum: also note, these figures imply that one computer with a modern CPU can dictionary attack a salted password hash file from a 1000-user site in merely 200 seconds, i.e. about the time it takes to microwave a burrito. No need to build a botnet first.
Essentially, MD5 and SHA were designed to be fast hashing algorithms. This is NOT what you want with password hashing, as you need to be able to tune the complexity of your algorithm to scale with Moore's Law and other factors.
He has also discussed this in depth here in the past if you search back over his comments (tptacek)
1. http://chargen.matasano.com/chargen/2007/9/7/enough-with-the...