|
Message-ID: <CANWtx00k192ZXKh80vgAt2Q=wbKt3qwGPXRHzh4ZLHztH4ft7g@mail.gmail.com> Date: Tue, 17 Apr 2012 17:04:27 -0400 From: Rich Rumble <richrumble@...il.com> To: john-users@...ts.openwall.com Subject: Re: .chr files On Tue, Apr 17, 2012 at 4:35 PM, jfoug <jfoug@....net> wrote: >>From: Frank Dittrich [mailto:frank_dittrich@...mail.com] >> >>Of course, if we find a large set of saltless hashes which more reliably >>represent real-life passwords, we should use this one instead. > > By far, the 'best' source to date has been the original non-unique RockYou > database leak. > > That is the entire DB, the easy PW's, and the super hard. Real life seems to be relative, would it make any sense to apply "policy" filters to something like the Rockyou list (one uppercase, one digit and one special char as an example policy filter) and then make a .chr file (name it policy-1U-1D-1S.chr)? I suppose a case can be made that an all.chr is more versatile, but could you also say that the filter is slower (I don't know if that is really true) and a dedicated .chr file would be faster. Perhaps it's time I experiment with exactly that :) -rich
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.