Live data from Hacker News

The FBI stole an Instapaper server in an unrelated raid

blog.instapaper.com

261–263 of 263 posts

Re: The FBI stole an Instapaper server in an unrelated raid

#262
post #186
post #25

Instapaper stores only salted SHA-1 hashes of passwords, so those are relatively safe. -- Obligatory statement on NEVER USING SHA-1 HASHES to make passwords "safe". Any normal person can brute force millions of SHA-1 hashes (salted however much you want) per second on a GPU. If the FBI so wanted (although I don't believe they do) I'm sure they could brute force almost every single password in that database. Granted,…

This is more "crypto nerd imagination", a la the XKCD comic. The FBI doesn't care about the encrypted passwords because it has access to all the content in plaintext. And what else would they need the passwords for? Other accounts on other services? They can just confiscate those servers too, where the content is most likely also in plaintext. So in this case , where the FBI is involve, using a SHA-1 hash poses no ex…

"So in this case, where the FBI is involve, using a SHA-1 hash poses no extra security vulnerability."

meeeh...

remember the fbi is not a person, it's an organization. the org can have bad actors in it who might be able to access the encrypted passwords but not be able to confiscate servers.

also, confiscating a server(s) is much more visible / detectable...

Re: The FBI stole an Instapaper server in an unrelated raid

#263

Earlier quoted context omitted.

There are systems you can use to defeat this. One password decrypts the drive, another wipes it.

If there was a court order for the decryption keys for your drive and you gave them a key that destroyed it, you would almost certainly be found guilty of deliberately destroying evidence.

If they could prove that that's what you did.
Post reply on HN