Hacker News new | ask | show | jobs
by dpc_01234 929 days ago
I think you're right. Reported on Syncthing forum. https://forum.syncthing.net/t/entropy-of-untrusted-device-sc...
1 comments

>> Is it less safe to share the “Default Folder” as encrypted then? Its folder ID is always just 'default'.

> In the sense that someone could easier pre-brute-force all passwords for that specific folder ID, yes.

That's the definition of a rainbow table, and a fixed, known folder ID makes the "salt" effectively worthless.