Hacker News new | ask | show | jobs
by seefoma 4407 days ago
This is actually about as good as it gets for password hashes, so kudos to eBay.

Since these are salted and require 12000 iterations, cracking individual passwords will be quite time consuming. The preferred method in this case, though, is to go after low hanging fruit.

The way one would do this is to try something like the 500 most common passwords against all entries in the table. This won't take very long (compared to trying to brute force a bunch of individual passwords), and will probably yield a ton of passwords.