This is like that Catalonia hashed database for voter identification that ended up outing national ID / birthday / zipcode associations. Hashes aren't magical pixie dust. If the search space is bruteforceable, they amount to the illusion of security.
-
Show this thread
-
If you *must* do this (and understand the risks), either use full legal names to maximize entropy and a very strong salted hash, like say bcrypt/scrypt tuned to take 5 seconds per hash on a CPU, or similar...
2 replies 3 retweets 15 likesShow this thread -
... or use a very *weak* hash, like the 6-digit prefix of the SHA1 (24 bits), to guarantee collisions and thus make it a probabilistic filter and not something you could brute force usefully.
5 replies 1 retweet 18 likesShow this thread -
Replying to @marcan42
Keeping there names a secret is not the point. Its against it actually. It just about getting some time to find others, without dropping a plaintext Google spreadsheet.
1 reply 0 retweets 0 likes -
Replying to @harce
I know. And I'm saying that won't work after someone writes a Twitter bot to reverse the hashes in seconds for the lulz, turning the approach into the equivalent of a plaintext Google spreadsheet.
1 reply 0 retweets 1 like -
Replying to @marcan42
Oh wow, public records that are meant to be accessible for other interested people are not fully secure? Who in the sec community would see that coming?!
1 reply 0 retweets 0 likes -
Replying to @harce
I dunno, ask the OP, she seems to think it's not a problem and not worth discussing, considering, or making clear to those using this scheme.
2 replies 0 retweets 0 likes -
Replying to @marcan42
Protip; outing sexual predators is not a threat, its the point. If smbd decrypts the hash it ain't them making the accusations public. WTF do you expect them to do with salts if they are looking for people who are only connected to them by a "shared secret" which they use....
1 reply 0 retweets 0 likes -
Replying to @harce
Pro tip: if A posts a hash of B's name and C cracks it, C isn't going to get the blame and media attention for incriminating B. A is.
1 reply 0 retweets 0 likes -
Replying to @marcan42
Not the case in most anglosaxon legal systems AFAIK.
1 reply 0 retweets 0 likes
Got any citation for that? Case law or legal analyses on how encryption or hashing interacts with libel laws? That would be a fun read.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.