Quantcast
Channel: Active questions tagged blowfish - Information Security Stack Exchange
Browsing index pages (28 articles)
↧

Why is Blowfish Cipher considered now "legacy" algorithm in OpenSSL?

I am not a security expert, so please forgive me if the question is too obvious. We have been working with Blowfish to encrypt some of our files. We recently updated our very old OpenSSL version from...

View Article


How to decrypt Blowfish Advanced CS encrypted file

Cleaning up my disk space, I found an encrypted file (*.bfa), which I encrypted with Blowfish Advanced CS (Version 2.13.00.002) about 15 years ago.I still have a copy of the original version of Bfacs,...

View Article


Why PHP password_hash does use blowfish intstead threefish?

I was wondering why PHP's hash_password function use blowfish instead of threefish. According to Bruce Schneier blowfish is outdated and He is recommending twofish or threefish. Is blowfish enough...

View Article

If the bitcoin network was cracking bcrypt, what cost factor would you use?

Since the best example of pooled resource to crack hashes is the bitcoin network, currently churning through 2.14 ExaHashes/s.I want to ask, if the resources of this network were pointed towards...

View Article

Is Blowfish validated against any standards?

OWASP ASVS 3.0 V7.7 states the following:Verify that cryptographic algorithms used by the application have been validated against FIPS 140-2 or an equivalent standard.Blowfish is not included in NISTs...

View Article


Explain BCrypt like I'm 5

I know this is a little bit broad, but I'd like to understand the function of this algorithm by explaining like I'm 5. And I'd like to know the difference between BCrypt and blowfish, is it because...

View Article

Is multiple encryption a good idea?

I know that many encryption algorithms, while secure, have vulnerabilities.To reduce risks, would multiple encryption like thisBlowfish_CbC ( Rc2_OFB ( AES128_CBC (myfilecontent)))be a good idea?I know...

View Article

Why do most hashing functions produce hashes that have characters a-f 0-9?

This is something I never understood about hashing functions. I know that algorithms like whirlpool and blowfish both produce outputs that don't follow this pattern, but why is it that most do? Is it...

View Article


How many rounds should be used to hash card numbers?

We want the ability for payments made without logging in using one of their saved payment methods to be associated with the saved payment method. E.g. if they buy a recurring subscription to magazine 1...

View Article


Strength Blowfish and DES with current quantic computing and mandating backdoors

What is the strength of algorithms such as DES (Rijndael) and Blowfishused in password manager Safe password, with the current development (2018) of quantum computing, the former parallel processing,...

View Article

Mathematically, how long would it take to crack a bcrypt password hash?

So I'm currently using bcrypt to hash passwords with a randomly generated salt (as seen in the pip bcrypt module), with 12 rounds.I have been looking around, but I cannot find a detailed and clear...

View Article

openssl speed tells me blowfish is much quicker than md5, what am I missing?

So I ran openssl speed md5 && openssl speed blowfish and blowfish seem quicker than md5.Here are the results (ran on windows WSL).$ openssl speed md5 && openssl speed blowfishDoing md5...

View Article

OpenSSL 1.0.1t does not decrypt with -bf if encrypted with OpenSSL version...

I have encrypted a file with the same command line with two different openssl versions: 1.0.1t and 1.1.0e. Then I try to decode both with version 1.0.1t and I cannot decode the latter.Can you please...

View Article


How do I generate a blowfish password hash in Ubuntu?

What's the command line to generate a blowfish password hash? I can't seem to figure this out at all. Apache's htpasswd only supports bcrypt, and openssl passwd doesn't even do blowfish hahes (but it...

View Article

Is bcrypt safe with the 64-bit block cipher birthday attack?

Recent research made it apparant that birthday attacks are now 'viable' on 64-bit block ciphers which Blowfish uses. (the paper in pdf)At work we use BCrypt for password hashing, as I was thought that...

View Article


Why are application/services still using outdated Blowfish encryption? Is it...

For example, CrashPlan, an online backup service, is using 448-bit Blowfish to encrypt its backup files (only enterprise product line has the ability to choose using AES-256). According to Blowfish's...

View Article

Can SSL using Blowfish cipher be considered strong enough?

I use OpenVPN to connect to a public VPN. Sometimes I connect from my college campus (it's fully open to alumni) and when this happens I can only use TCP SSL because the college network has a security...

View Article


“Official statement” on php.net : CRYPT_BLOWFISH is strongest hash algorithm....

First: I asked this question on stackoverflow and was kindly asked to post this here again. See the original question here.According to the [early] doc pages of the new PHP 5.5 password...

View Article

Bruteforcing blowfish

I am quite new to encryption and recently played around with blowfish (openssl's implemenation).I am using a 23 character password (case-sensitive alphanumeric random). I estimate the entropy to be...

View Article

Is AES(Rijndael) faster than Blowfish?

I know theoretical that blowfish is much faster than aes. But I benchmarked several algorithms including aes and blowfish for 1MB, 5MB, 10MB etc. files in java 8 platform and bouncy castle library. In...

View Article
Browsing index pages (28 articles)


Latest Images