Brute forcing 2^64 bits means calculating 2^63 MD5s in expectation. You can do ~100 GHash/sec, so ~2^37/s, so about 2^29s which is 17 gpu-years. So this is doable, but incredibly expensive.
Brute forcing 2^64 bits means calculating 2^63 MD5s in expectation. You can do ~100 GHash/sec, so ~2^37/s, so about 2^29s which is 17 gpu-years. So this is doable, but incredibly expensive.
It was tempting to pick say 128-bits of randomness and SHA-512/256 where I'd stake actual money that it just cannot be done - but that's like twice as much die-rolling and typing. On the other hand if I do 32-bits (fewer rolls) and MD5 there's probably some loser out there who has already precomputed all of those for whatever reason and then somebody finds the answer with a Bing search and doesn't end up learning anything.
echo -n 'F004672790DB5B1D' | md5sum
f31fb042501c2a398974feca81afd8fa -MD5 and SHA are specifically designed to be fast to compute, they shouldn’t be used for passphrases.
Figured I’d bring it up in case there’s still PHP floating around with the once-typical practice of MySQL + MD5.
I suppose I thought of 64bit as now being small. 48 would be doable.