Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can't we just submit bogus hashes?


Generally that is countered by asking for a mix of known and unknown solutions; your accuracy on the unknown is assessed through your accuracy on the known.


Is it possible to do some other sort of cryptographic trick than simply seeding the mix with known and knowns. Some sort of sum of many answers combined? Maybe it isn’t possible in this use case though (brute forcing passwords). For example is crypto POW really just doing a mix of known and unknowns or is there more cryptographic magic to it than that?


But there are only a few suspect passwords, you can just know all of them, and thus reliably differentiate.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: