char[] entered+_hash = ...
char[] password_hash = ...
for (int i = 0; i < entered_hash.length; i++)
if entered_hash[i] != password_hash[i]:
return false;
return true;
This is a modification of a dictionary attack. as such, it assumes that the person has used a known password.I take a standard password dictionary and hash everything. I arrange it into a Trie or somesuch by the hash.
I start trying passwords. Specifically: I try passwords where the first character of the hash is different. So, for instance, with SHA256, I try:
12345 5994471abb01112afcc18159f6cc74b4f511b99806da59b3caf5a9c173cacfc5
abc123 6ca13d52ca70c883e0f0bb101e425a89e8624de51db2d2392593af6a84118090
computer aa97302150fce811425cd84537028a5afbe37e3f1362ad45a51d467e17afdc9c
123456 8d969eef6ecad3c29a3a629280e686cf0c3f5d5a86aff3ca12020c923adc6c92
1234 03ac674216f3e15c761ee1a5e255f067953623c8b388b4459e13f978d7c846f4
a1b2c3 4f32044a655f32e8528edea64dbfd11cba810b8790e6e6e23d28ad3a75980734
xxx cd2eb0837c9b4c962c22d2ff8b5441b7b45805887f051d39bf133b583baf6860
test 9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08
carmen f3c2ce176290b0c384cb4881eb714f2db58f630c33863d91c9bedf58d36007db
mickey 33c614ca3cf78827a85dc0d8d06bfcf8c4d923fd23c813acd50b80ed2d4d4fb3
secret 2bb80d537b1da3e38bd30361aa855686bde0eacd7162fef6a25fe97bf527a25b
summer e83664255c6963e962bb20f9fcfaad1b570ddf5da69f5444ed37e5260f3ef689
ranger dbc4a04327176e6577b4da46df04564150053960eba5d89587dad1f76a818d80
letmein 1c8bfe8f801d79745c4631d09fff36c82aa37fc4cce4fc946683d7b336b63032
mindy 7376c22801fbd6e01009830a70028820f280958165e6d3c2bac9683dab28feb7
bear bc98bb50e8094b2ac3ceb90ba2512587c0513cd294a07efcfdcf467198da6266
One of these should take slightly more time than the others. Let's say it's 'carmen'. I now know that the first character of the password hash is 'f'. I then try passwords where the first character of the password hash is 'f' and the second is different. Repeat until I have the entire password.Note that this can also turn an online brute-force attack into an offline brute-force attack with a small online component. (The only difference being instead of a password dictionary, you brute-force for hashes with the known bits.)
Note that a salt - if the salt is never leaked - prevents this attack.
(Except that if you have an account yourself you can do a timing attack against your own account to try to figure out the salting scheme!)
--------
If the password hash itself takes data-dependent time... There are plenty of ways to go from that to breaking passwords. I could elaborate if you wish.