Whitepixel v2 now brute forcing 33.1 billion password/sec
blog.zorinaq.com
blog.zorinaq.com
That's pretty impressive.
Think of all the BitCoins they could create with a setup like that (I get an average of 50 coins every 26 minutes with http://www.alloscomp.com/bitcoin/calculator.php).
At a current market value of about USD$0.22 per coin, this equates to about USD$25/hour.
Of course, BitCoin uses SHA256, but how much different from MD5 can that be?
(MD5: 128 bit | SHA256: 256 bit) :: (2^256/2^128 = 2^128) => 3.40282367*10^38 of a larger keyspace.
I know nothing about the specifical implementation details of either hashing method (and I eagerly await tptacek to offer a far more comprehensive response) but I'm sure the difference in keyspace alone is enough to make this practically impossible.
a) One does not pay for resources consumed. b) Speculates about future value of BTC.
Regardless, very impressive. I would love to hear more!
Maybe this is the final incentive for me to look into EC2...
(This is the machine I built to develop whitepixel).
If someone finds a way to generate,say, 5x more bitcoins that what the average expected amount is - they have a temporary advantage, but once those coins hit the market, the market is diluted and will quickly catch up.
Bitcoins has replaced mining gold with generating bitcoins - so it will be harnessing server infrastructure and good code / math -vs- digging big holes in the ground.
Usage: ./whitepixel [OPTION]... [<hash>]
Main arguments:
-c <charset> Generate candidate passwords using the specified charset
which can be:
lower Lowercase
upper Uppercase
digit Digits
print Printable ASCII characters and space [0x20-0x7e]
all All bytes [0x00-0xff]
(default: lower)
-l <length> Attack passwords of this length (default 5)
<hash> MD5 hash to attack (default 00...00)This only gets faster, not slower. No matter how much you salt your passwords, soon they will be able to crack your passwords fast enough. And soon there will be rainbow tables of salts.
If you have a seriously good reason for not using either of these, which you probably don't, "stretched" (iterated thousands of times) and salted SHA-2 or MD5, or PBKDF2 ( http://en.wikipedia.org/wiki/PBKDF2 ) can be acceptable alternatives.
(Windows' newest password hashing algorithm, NTLM, is just a plain MD4 hash of the password. I estimate my 4x5970 machine can crack NTLM hashes at a rate of about 45 billion per second.)
Technically, NTLM will always be the "newest" unless they invent something newer, but it doesn't mean you need to use it.
How am I misleading?