Skip to content

WindowsTechs.com

Collaborate Disseminate

Menu

Primary menu

  • Home

Author Archives: MechMK1

How bad would a partial hash leak be, realistically?

Posted on May 31, 2019 by MechMK1

Even though the current recommendation for storing passwords is the usage of a slow key derivation function such as Argon2, scrypt, PBKDF2 or bcrypt1, many websites still use the traditional hash(password + salt) method, with… Continue reading How bad would a partial hash leak be, realistically?→

Posted in hash, password cracking

What are the minimum parameters for Argon2?

Posted on May 29, 2019 by MechMK1

Argon2 is the winner of the Password Hashing competition, and currently recommended by OWASP for secure storage of passwords.
One crucial step of Argon2 is determining the parameters used by the function. The current IETF draft titled &quo… Continue reading What are the minimum parameters for Argon2?→

Posted in argon2, hash

How to rate CVSS3’s "Privileges Required" when an attacker can create an account?

Posted on May 27, 2019 by MechMK1

The Common Vulnerability Scoring System Version 3.0 rates the severity of vulnerability depending on factors such as:

Attack Vector (AV) – What kind of access does an attacker need? Can they do it over the net or do they ne… Continue reading How to rate CVSS3’s "Privileges Required" when an attacker can create an account?→

Posted in cvss

Does it pose a problem to use ‘strict-dynamic’ with a hash and not a nonce?

Posted on May 17, 2019 by MechMK1

Ever since CSP 3 introduced strict-dynamic, Google has recommended its usage. Indeed, the idea of maintaining one “root” script, which in turn loads all other necessary scripts, sets up event handlers, etc. instead of maintai… Continue reading Does it pose a problem to use ‘strict-dynamic’ with a hash and not a nonce?→

Posted in content security policy

Is Diceware more secure than a long passphrase?

Posted on April 24, 2019 by MechMK1

I recently investigated best-practices in regards to passwords, and the overwhelming majority of sources recommended using a password manager. This is great advice, but not usable in every situation. Certain situations, such … Continue reading Is Diceware more secure than a long passphrase?→

Posted in entropy, passwords

How can a Web Server be fingerprinted?

Posted on April 17, 2019 by MechMK1

How can a Web Server such as nginx or Apache be fingerprinted, if only functional HTTP Headers are sent and error pages are replaced by custom ones?

Continue reading How can a Web Server be fingerprinted?→

Posted in webserver | Tagged fingerprinting

Post navigation

Newer posts →

Primary Sidebar Widget Area

Infocon Status

Internet Storm Center Infocon Status

Recent Posts

  • Will Maryland’s Utility Bills Increase $1.6B to Support Other States’ Datacenters? May 9, 2026
  • Rush Rescue Mission for NASA’s $500M Space Telescope Passes Key Milestone May 9, 2026
  • Conti Leaks – Sample Statistics and Graphs – An Analysis May 9, 2026
  • Email Address Accounts for Breached Forums – Part Two May 9, 2026
  • Email Address Accounts for Breached Forums May 9, 2026

Tag Cloud

Agriculture Alzheimer's Disease Art Audio Automation Bluetooth Building and Construction Campervan Camping Cancer Coronavirus (COVID-19) Cycling Dementia Diabetes DNA Electric Vehicles Food Home House Huawei Indiegogo MIT Mobility Moon New Atlas Audio NVIDIA Off-grid Off-road Pedal-assisted Photography Physics Radio Repair RV Samsung Satellite Sony SpaceX spoofing sustainable design The Immune System Tiny Footprint Training Water Zoom

Archives

  • Facebook
  • Twitter
  • Linkedin
  • Email
Copyright © 2026 WindowsTechs.com. All Rights Reserved.
Theme: Catch Box by Catch Themes
Scroll Up