Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, absolutely.

Although MD5 is a little on the short side and collisions can be generated for it easily, it would still be a noteworthy breakthrough for someone to produce a primary preimage for MD5.

That's what it would take for someone to find a working password for your account given your salt and MD5 hash.

In other words, there are still no known cracking tools that can do much better than dictionary or brute force against MD5, so a very strong password is still very strong and a salted SHA-1 password would be only slightly stronger.



MD5 collisions don't matter for passwords, since you are very unlikely to hit one.


I think I said that. Perhaps you said it better.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: