10 Apr
2019
10 Apr
'19
12:41 p.m.
* Nick Hilliard via db-wg
Gert Doering wrote on 10/04/2019 11:08:
The attack vector against unsalted hashes is "rainbow tables"... make the API key something like 80 characters long, and no machine in the world can do anything but brute force.
which will work until the DB ends up on https://haveibeenpwned.com/
Guys, JFYI - https://lirportal.ripe.net/api/ already exists and the API keys it issues can apparently be used to maintain your RPKI data. It doesn't seem to me like adding the possibility for database maintenance via an API key make things any worse from a security standpoint. Tore