СΥѥɤ˾㳲ȤƻLinkedInǧ
ʲΥ֥ξ
ֲ桹躢ƳǤΥƥˤϡԤΥѥɥǡ١ΥϥåsaltޤޤƤꡢαƶǥѥɤѹ桼ˤ⡢ѥɤ˾㳲ƤʤСˤפͿ
ϥåsalt ǽʬʤΤϰʲκϿʥåץǡȤޤˤǡǯե奢Ρͥ褷
—————
ʡʥͥåȥ롼סAnonymousפ躢HBGary Federalȥ롼ȥåȥƥΥʬϤȳȯ쿴Ƥ륪饤եrootkit.comפϥårootkit.comפ桼ѥɤ˾㳲Ƥ롣
η˴ϢơץꥱƥǵäƤȥԥåʤѥɥϥåˤĤƻŦ
WebʤӤ¾Ρ˥ץꥱ桼ѥɤΥϥåMD5SHA1ޤSHA-256ѤƤꡢŪʥǥ٥åѤΥѥɤsaltƤ롣ƻĹǯϤäơsaltͤϤɤΤ褦٤ɤΤ餤ĹǤ٤ˤĤơǮܤˤƤ
ǰʤȤˡۤȤɤξ硢MDSHAϥåեߥϷ®٤Τ߷פƤꡢơrootkit.comפǵä褦ˡsaltͤΥƥϡԤʥȥäȤפǤϤʤȤ¤ƨƤ롣Ԥ롼ȥͭȤϤʤΥѥɡsaltӤʤѥɤǧ뤿˻Ѥ륳ɤ롣
ơɤʥƥ߷פǤŤ٤¬ϡԤоΤ٤Ƥ˥ǽǤ롢ȤȤ
saltϼȤơ쥤ܡơ֥ȤƤΤ롢줿ɻߤ뤳ȤŪȤƤ롣ƻ줿⤬ɻߤ¤ꡢȤԤ桼ѥɤȶsaltͤȤƤ⡢ѥɤŪȡ̤˿¬Ƥ
MDSHAϥåХꥢȤϡ®٤Τ߷פƤꡢϡѤΥӥǥեåǥץ쥤ɤѤȡԤ1ä˲Υ֥롼ȥեưפ˻ߤ뤳ȤǤȤȤ̣롣
ʲȡhttp://www.golubev.com/hashgpu.htm
ʤñATI HD 5970ǤԤ33ŵŪ쥤ܡơ֥2^52.5ϥåˤѥɥڡС뤳ȤǤ롢ȤȤ̣Ƥ롣ƥꥢʹԤŻʣΥɤѤƤ뤳Ȥϴְ㤤ʤ
Ԥʤsaltͤȥɤ硢桼ȤݸΤϡѤƤѥɤζ٤ʤ桹ϤޤꡢȥԡɤǤȤϸʤȥ֥롼ȥեμˡȤ߹碌뤳Ȥˤäơ¿ΥȤ絬ϥȤǤäƤ⡢ʤ̤ΥѥɤˤΤˡۤĹ֤Ϥʤ
Τ褦ʻ֤ˤϡɤ٤
ǽ˹ͤ٤Ȥϡѥɤζˤ˻ƤȤȤפʤΤϡȤˤΤɬפʥɤĹǤʤΤˤɤΤ餤λ֤ݤ뤫ȤȤ
ϡSHA1뤤¾Υץ졼ʥϥå奢르ꥺ餫ˡ奢ʥѥǧڸǤϤʤȤ̣Ƥ롣
桹ȤΤϡ֥롼ȥեФ̵ϤǤʤΤ1ä23λߤԤˡʤϹԤ10,000뤤100,000λߤ¤벿˾
saltͤλѤŬڤʥץơԲķǤΤΡʤ褹μ¤ˡǤϤʤΤ
ˤϡʲΥץѥƥѥɥϥå她बɬפ
• ѥ礷硢ɬפȤ֤ưפĴ᤹뤳ȤǤ롣
• ƥ桼ȿθֹͭĤȤǤ롣
• ƥ桼ϥå夬ˡǤꡢ2ͤΥ桼ƱѥɤǤ뤫ϥåӤΤ뤳ȤԲǽǤ롣
ʲ顢Ĥ֤ȤǤ롧
• PBKDF2 http://en.wikipedia.org/wiki/PBKDF2
• Bcrypt http://www.openwall.com/crypt/
• PBMAC http://www.rsa.com/rsalabs/node.asp?id=2127
• scrypt http://www.tarsnap.com/scrypt.html
Ϥ줾ζߤȼߤ뤬SHA1+saltΤ褦ѥϥåΥץơꡢϤ뤫˶Ϥ
äơʤѥɤäƤʤ顢嵭ΥΤ1Ĥӡ˾ޤ֡10200msʤɡ˥ФѥɤåȿβꤷѤ롣ԤȿȤФƻ褦ˤΤǤϤʤƥȤ˸̤˥ե褦ƥ桼ФƥˡsaltͤȿȤѰդ뤳Ȥ
ꥸʥεʤӥȡˤˤ롣
ʲΥ֥ξ
ֲ桹躢ƳǤΥƥˤϡԤΥѥɥǡ١ΥϥåsaltޤޤƤꡢαƶǥѥɤѹ桼ˤ⡢ѥɤ˾㳲ƤʤСˤפͿ
ϥåsalt ǽʬʤΤϰʲκϿʥåץǡȤޤˤǡǯե奢Ρͥ褷
—————
ʡʥͥåȥ롼סAnonymousפ躢HBGary Federalȥ롼ȥåȥƥΥʬϤȳȯ쿴Ƥ륪饤եrootkit.comפϥårootkit.comפ桼ѥɤ˾㳲Ƥ롣
η˴ϢơץꥱƥǵäƤȥԥåʤѥɥϥåˤĤƻŦ
WebʤӤ¾Ρ˥ץꥱ桼ѥɤΥϥåMD5SHA1ޤSHA-256ѤƤꡢŪʥǥ٥åѤΥѥɤsaltƤ롣ƻĹǯϤäơsaltͤϤɤΤ褦٤ɤΤ餤ĹǤ٤ˤĤơǮܤˤƤ
ǰʤȤˡۤȤɤξ硢MDSHAϥåեߥϷ®٤Τ߷פƤꡢơrootkit.comפǵä褦ˡsaltͤΥƥϡԤʥȥäȤפǤϤʤȤ¤ƨƤ롣Ԥ롼ȥͭȤϤʤΥѥɡsaltӤʤѥɤǧ뤿˻Ѥ륳ɤ롣
ơɤʥƥ߷פǤŤ٤¬ϡԤоΤ٤Ƥ˥ǽǤ롢ȤȤ
saltϼȤơ쥤ܡơ֥ȤƤΤ롢줿ɻߤ뤳ȤŪȤƤ롣ƻ줿⤬ɻߤ¤ꡢȤԤ桼ѥɤȶsaltͤȤƤ⡢ѥɤŪȡ̤˿¬Ƥ
MDSHAϥåХꥢȤϡ®٤Τ߷פƤꡢϡѤΥӥǥեåǥץ쥤ɤѤȡԤ1ä˲Υ֥롼ȥեưפ˻ߤ뤳ȤǤȤȤ̣롣
ʲȡhttp://www.golubev.com/hashgpu.htm
ʤñATI HD 5970ǤԤ33ŵŪ쥤ܡơ֥2^52.5ϥåˤѥɥڡС뤳ȤǤ롢ȤȤ̣Ƥ롣ƥꥢʹԤŻʣΥɤѤƤ뤳Ȥϴְ㤤ʤ
Ԥʤsaltͤȥɤ硢桼ȤݸΤϡѤƤѥɤζ٤ʤ桹ϤޤꡢȥԡɤǤȤϸʤȥ֥롼ȥեμˡȤ߹碌뤳Ȥˤäơ¿ΥȤ絬ϥȤǤäƤ⡢ʤ̤ΥѥɤˤΤˡۤĹ֤Ϥʤ
Τ褦ʻ֤ˤϡɤ٤
ǽ˹ͤ٤Ȥϡѥɤζˤ˻ƤȤȤפʤΤϡȤˤΤɬפʥɤĹǤʤΤˤɤΤ餤λ֤ݤ뤫ȤȤ
ϡSHA1뤤¾Υץ졼ʥϥå奢르ꥺ餫ˡ奢ʥѥǧڸǤϤʤȤ̣Ƥ롣
桹ȤΤϡ֥롼ȥեФ̵ϤǤʤΤ1ä23λߤԤˡʤϹԤ10,000뤤100,000λߤ¤벿˾
saltͤλѤŬڤʥץơԲķǤΤΡʤ褹μ¤ˡǤϤʤΤ
ˤϡʲΥץѥƥѥɥϥå她बɬפ
• ѥ礷硢ɬפȤ֤ưפĴ᤹뤳ȤǤ롣
• ƥ桼ȿθֹͭĤȤǤ롣
• ƥ桼ϥå夬ˡǤꡢ2ͤΥ桼ƱѥɤǤ뤫ϥåӤΤ뤳ȤԲǽǤ롣
ʲ顢Ĥ֤ȤǤ롧
• PBKDF2 http://en.wikipedia.org/wiki/PBKDF2
• Bcrypt http://www.openwall.com/crypt/
• PBMAC http://www.rsa.com/rsalabs/node.asp?id=2127
• scrypt http://www.tarsnap.com/scrypt.html
Ϥ줾ζߤȼߤ뤬SHA1+saltΤ褦ѥϥåΥץơꡢϤ뤫˶Ϥ
äơʤѥɤäƤʤ顢嵭ΥΤ1Ĥӡ˾ޤ֡10200msʤɡ˥ФѥɤåȿβꤷѤ롣ԤȿȤФƻ褦ˤΤǤϤʤƥȤ˸̤˥ե褦ƥ桼ФƥˡsaltͤȿȤѰդ뤳Ȥ
ꥸʥεʤӥȡˤˤ롣