Bullshit. MD5 is just fine, as long as you use the salt.
Here, hack this:
MD5(password + salt) = "b520542710812f347432232b2a1fba83"
salt = "MD5 rules"Bullshit. MD5 is just fine, as long as you use the salt.
Here, hack this:
MD5(password + salt) = "b520542710812f347432232b2a1fba83"
salt = "MD5 rules"It will explain why "salts are useless for preventing dictionary attacks or brute force attacks."
The entire article is excellent - and every colleague who I've ever pointed at it, has come away nodding their head and seeing the light.
The key-takeway (but please, read the entire article) is: "It doesn’t affect how fast an attacker can try a candidate password, given the hash and the salt from your database."
Salts only help you from precomputed dictionary attacks ("Rainbow Tables") - but, if someone is brute forcing you, the value of a salt just disappeared.
Sure, a very large salt might slow down the first iteration a little (but not necessarily subsequent ones, and it wouldn't require more memory, at least with most hash functions), so you're almost always better off just stretching the key--then you save the storage costs too.
$ echo -n "Spiderpig1MD5 rules" | md5sum
b520542710812f347432232b2a1fba83 -
Thus the password here is "Spiderpig1"MD5 is broken.
Use bcrypt or scrypt. Don't make up your own crypto.
[1] Crypto benchmarks: http://www.cryptopp.com/benchmarks.html