Also, he worries about the PIN being stored somewhere in plain text. If one-way hashes were used, anyone obtaining the hash would only need to test it against 10k possible values to get the original.
Also, he worries about the PIN being stored somewhere in plain text. If one-way hashes were used, anyone obtaining the hash would only need to test it against 10k possible values to get the original.
Even using bcrypt set to take 1 second to verify a hash wouldn't be great -- it'd take about two hours and 45 minutes to break a PIN. And yes, while this is significantly better than not hashing at all (where it takes no time to get a pin) it would be trivial to target specific people to get their pin's given the hashed database.
Sure, you could make it take 10 seconds to verify a hash, but now all you've done is make me take a day to break the pin.
Still a pretty small rainbow table, I guess.
HMAC means Hash based Message Authentication Code.
HMAC(K,m) = H((K ⊕ opad) ∥ H((K ⊕ ipad) ∥ m)).
HMAC(key, password) instead of hash(password) or hash(salt+password)