[00:07.550 --> 00:09.270] Can everyone hear me? [00:09.790 --> 00:10.050] No. [00:11.070 --> 00:11.790] Gotta flip it on. [00:21.210 --> 00:22.450] You like that, guys? [00:23.690 --> 00:24.510] Check, check. [00:24.930 --> 00:26.470] Oh, there we go. [00:26.970 --> 00:28.050] How many of you guys like Red Bull? [00:29.430 --> 00:29.870] Yeah? [00:36.440 --> 00:37.840] How many of you guys like Jaeger? [00:44.550 --> 00:45.310] That's the shit. [00:47.010 --> 00:48.650] Alright, that will get me going for the time. [00:48.650 --> 00:50.210] Alright, my name... [00:51.050 --> 00:55.350] This is my first time speaking at HOPE, and mostly it's like, who the hell are these guys? [00:56.470 --> 00:59.190] They come from nowhere, first time speakers, all this stuff. [01:00.610 --> 01:09.290] I'd like you to know who I am before I talk to you, because I'm going to want to get to know you guys a little bit, figure out whether we have a lot of black hats, gray hats, white hats, the general crowd of everything. [01:10.070 --> 01:13.730] I want to explain a little bit today about password cracking, timeary trade-off. [01:13.890 --> 01:24.210] It is so taboo, because a lot of the presentations here at HOPE have been a little bit, I don't know, let's hack the metric cards, or coupon hacking, stuff like that. [01:24.350 --> 01:25.510] More true hacker sense. [01:25.690 --> 01:30.190] I'm going to get down into a little bit of the shady area of hacking in general. [01:30.610 --> 01:32.690] My name on the screen, Jason Ardaeus. [01:32.990 --> 01:34.910] I'm an information security officer. [01:35.390 --> 01:41.710] Basically, what I do is I audit policies for a lot of hospitals, banks, and law firms in the Chicagoland area. [01:42.170 --> 01:48.070] I also do... I spend a lot of time in research, because research is what, you know, our future is. [01:48.210 --> 01:54.950] So I like to, you know, develop new techniques, just basically become the trust into the hacker, just toilet stuff, and move on in my life. [01:54.950 --> 01:57.820] I got a bachelor's in network and communications management. [01:58.330 --> 02:03.070] I got it from IIT in Chicago, and I finished a lot of it in my work at ISU. [02:03.970 --> 02:06.310] So, who knows what password cracking is? [02:07.290 --> 02:07.870] Come on. [02:08.150 --> 02:09.090] Give me a couple definitions. [02:09.430 --> 02:10.630] And I'll repeat them for the mic. [02:12.170 --> 02:14.030] All the hands, but no definitions. [02:15.530 --> 02:16.470] Recovering a password. [02:16.730 --> 02:17.710] Recovering a password. [02:17.870 --> 02:25.210] Basically, in essence, it's the art of deciphering or decrypting information within the realm of passwords. [02:25.410 --> 02:27.790] Because you can have cracking in many essences. [02:28.010 --> 02:29.150] You can crack software. [02:29.390 --> 02:33.050] And that's decrypting or deciphering something in the software, right? [02:33.050 --> 02:33.310] And that's what we're talking about. [02:34.350 --> 02:34.750] And that's what we're talking about. [02:34.750 --> 02:36.950] Who knows what time memory trade-off is? [02:44.840 --> 02:45.240] Yeah. [02:45.660 --> 02:50.820] Basically, what it is, it's a time-to-memory comparison. [02:51.060 --> 02:54.100] Basically, it's a comparison of two elements. [02:54.240 --> 02:56.100] You can have, they do the same thing in horse racing. [02:56.240 --> 02:59.080] It's 1 to 2, 10 to 20, space to time. [02:59.200 --> 03:00.900] There's a whole bunch of different comparisons in there. [03:01.200 --> 03:07.860] The trade-off, in essence, is an exchange of one thing that you want, but you're willing to give up something for that. [03:07.860 --> 03:10.500] For instance, the Wikipedia definition. [03:10.720 --> 03:16.380] Exchange of one thing for another, especially relinquishment of one benefit or advantage for another, regarded as more desirable. [03:17.580 --> 03:20.980] When you combine the two, this is what I want to be talking about. [03:21.080 --> 03:25.100] When you take time memory and you apply it to password cracking. [03:25.480 --> 03:31.400] Instead of generating all possibilities every time, such as in brute forcing, how many of you guys brute force? [03:32.640 --> 03:33.340] Ah, ah, ah, yeah? [03:33.760 --> 03:33.920] All right. [03:34.580 --> 03:42.560] There are a lot of brute-forcers out there, and quite honestly, in my profession, I don't have three hours to run against a secure password. [03:42.680 --> 03:45.600] Does anybody have three hours to just wait and let the brute forces run? [03:45.720 --> 03:45.880] No. [03:46.160 --> 03:47.620] It's just sort of a waste of time. [03:48.360 --> 03:50.220] Instead of that, you generate all of them. [03:50.400 --> 03:54.900] You store them one time into memory, a hard drive, something like that. [03:54.900 --> 04:06.540] And then every time you go to recall that information, you can quickly make a query to a database, a flat file database, something like that, and instantly get the decrypted password from a hash or something like that. [04:07.880 --> 04:13.820] For my site, md5lookup, we can decrypt md5 hashes in under a second. [04:14.000 --> 04:16.580] And a seven character password, instantly. [04:16.820 --> 04:17.960] And I'm going to demo that later. [04:18.100 --> 04:24.860] And then I also have a multi-cracker, which will do a list of hashes, and I can do 60 passwords in under a minute. [04:25.080 --> 04:26.500] So I'll demonstrate that later. [04:27.500 --> 04:29.380] A little outline of what I'm going to be talking about. [04:34.200 --> 04:36.040] A little bit of the history of password cracking. [04:36.840 --> 04:38.180] Ciphering relatively boring stuff. [04:38.400 --> 04:39.720] I'm not going to spend much time on that. [04:40.340 --> 04:41.580] Past and present, obviously. [04:41.840 --> 04:44.220] I'm going to get some information from you guys, see where you guys are at. [04:44.420 --> 04:49.760] The timer and trade-off basics explain to you exactly what time the memory is in the trade-off when it's applied. [04:50.160 --> 04:54.740] I'm going to give you some of the storage requirements, how much space a lot of these databases require. [04:54.740 --> 04:58.440] They can be 200 gigs to 2 terabytes. [04:58.680 --> 05:01.380] And right now we're pushing like the 1.8 terabyte range. [05:01.880 --> 05:04.020] So, there's a couple techniques. [05:04.360 --> 05:06.140] How many of you guys have ever heard of rainbow tables? [05:07.380 --> 05:07.760] Yep. [05:08.100 --> 05:14.500] Really popular application, but very weak and statistically inaccurate because of the fact of the math that's used behind it. [05:15.440 --> 05:17.180] There are two types out right now. [05:17.280 --> 05:20.400] The type that I've been developing, which is a true hash database. [05:20.920 --> 05:22.320] It's a one-to-one comparison. [05:22.320 --> 05:32.040] And then there's rainbow tables, which uses really funky mathematics to get around the massive storage requirements that are required by MD5 looking up and multi. [05:32.580 --> 05:36.500] I'm going to be doing demonstrations of both, give you a little history of how I got to where I'm at. [05:36.780 --> 05:46.420] And then, if time permitting, I'm going to go over how we basically, since the first revisions of the database were so huge, we couldn't even hold a candle to rainbow tables. [05:46.620 --> 05:54.460] So, we had to think of something to cut the sizes down on these huge password databases so that we could compare to rainbow tables and actually compete in the password cracking market. [05:54.640 --> 05:59.160] So, what we did was we did a bunch of magic with CRCs to really get over that. [05:59.500 --> 06:00.560] So, let's get going. [06:01.020 --> 06:01.200] All right. [06:02.600 --> 06:03.680] Basically, brief history. [06:04.600 --> 06:07.220] Ciphering, deciphering has been around forever, and that's just... [06:07.220 --> 06:08.300] everybody knows that. [06:08.300 --> 06:11.360] It's been used in wars, modern culture, and never fails. [06:11.500 --> 06:16.180] People have used encryption for messages, telephones, their PCs. [06:16.540 --> 06:20.300] And when the PC came around, there was this huge... [06:20.300 --> 06:24.180] Originally, what they used was user permissions to protect passwords and stuff. [06:24.300 --> 06:26.440] Everything was stored in regular plain text. [06:26.740 --> 06:30.300] And after a little while, you got into the multi-user environment. [06:30.440 --> 06:31.480] Well, you couldn't do that anymore. [06:31.640 --> 06:36.240] So, now they had to come up with algorithms to encrypt the passwords and put them in a password file. [06:38.020 --> 06:42.720] That, basically, that technique has been pushed all the way until today. [06:42.880 --> 06:43.940] That's what we use today. [06:44.080 --> 06:46.860] We use password files loaded with encrypted hashes. [06:47.360 --> 06:48.940] And part of that is the problem. [06:49.380 --> 06:49.820] So... [06:49.820 --> 06:53.360] And, basically, encryption can be applied to any type of communication. [06:53.660 --> 06:54.500] A little history. [06:54.900 --> 07:01.440] Random guessing, which was, basically, you walk up to a password prompt and you type, you know, God, sex, and something else. [07:01.540 --> 07:02.580] The top four or five. [07:02.740 --> 07:03.600] And you see if you can get it. [07:03.600 --> 07:08.200] Educated guessing is when you know something about your target, your desired target. [07:08.340 --> 07:14.480] For instance, if I know my target has a dog named Bruno or whatever, I'm going to type in Bruno. [07:14.620 --> 07:15.760] The biggest one is the girlfriend. [07:16.020 --> 07:19.580] People don't use your girlfriend, boyfriend's name as your password. [07:19.740 --> 07:20.340] It is so bad. [07:20.820 --> 07:23.260] Pattern matching is what a lot of the older... [07:23.260 --> 07:29.620] What they used to do was, when the Japanese would, let's say, in the war, the Japanese would encrypt a message and they'd send it across. [07:29.620 --> 07:34.440] What they'd do was grammatical and word matching to see how many... [07:34.440 --> 07:37.520] Okay, this word is three letters, so we know that it's got to stay in the three-letter realm. [07:37.640 --> 07:40.680] And then they'd just try and pattern match the entire message together. [07:41.220 --> 07:49.040] And then the most common and the most prominent way of password cracking nowadays, also the longest and most tedious thing I've ever done in my life, is brute forcing. [07:49.580 --> 07:56.960] Try every single combination that you can possibly try in a set character set and just see if one matches. [07:57.140 --> 08:00.320] And if it doesn't, well, you've got to choose a new character set and start all over. [08:01.100 --> 08:09.920] Not only is that just... that's the most vain thing I've ever heard, and that's what drove me to get into something else, and that's why time memory trade-off is so popular now. [08:10.620 --> 08:13.480] The other thing was the classic dictionary attack. [08:14.280 --> 08:22.400] It's... because of the fallacy of having to restart every time, they applied the dictionary attack, which has definitely boosted the effectiveness of brute forcing. [08:22.820 --> 08:27.300] I mean, brute forcing in and of itself isn't too bad of a thing, but it's just too slow for... [08:28.080 --> 08:29.360] when you're trying to... [08:29.360 --> 08:34.760] when you definitely have 500 passwords or hashes that you need to reverse, you can't brute force them all. [08:34.860 --> 08:36.180] It's just going to take way too long. [08:38.960 --> 08:42.100] Here's basically the past state of computing. [08:42.860 --> 08:45.360] How many of you remember when we had 5-gig hard drives? [08:45.720 --> 08:46.980] That was the big deal. [08:47.620 --> 08:47.740] Okay. [08:47.860 --> 08:50.740] Well, how many of you remember the old SRAM and the PC100? [08:51.340 --> 08:52.520] The Pentium 1. [08:52.680 --> 08:53.580] All that stuff. [08:53.820 --> 08:55.580] The dreaded ISIS lot. [08:56.180 --> 08:56.260] Okay. [08:57.260 --> 08:58.140] DOS 6.22. [08:58.420 --> 08:58.840] Mac OS. [08:59.100 --> 08:59.440] UNIX. [08:59.540 --> 09:01.580] You're talking about all the old school stuff that... [09:01.580 --> 09:04.840] a lot of the guys that were speaking at this conference, they grew up on that stuff. [09:07.820 --> 09:09.840] What are a few things that have changed since then? [09:13.420 --> 09:13.860] Processors. [09:13.860 --> 09:14.000] Processors. [09:14.220 --> 09:14.880] Hard drives. [09:15.460 --> 09:16.360] All that stuff. [09:16.700 --> 09:18.800] Hard drives are through the roof. [09:19.000 --> 09:21.940] Hitachi just released a 750-gigabyte hard drive. [09:22.100 --> 09:23.760] And that's like a $500 purchase. [09:23.920 --> 09:27.760] So you can raid these things together and have a massive array for relatively cheap. [09:28.020 --> 09:30.480] Memories, CPUs, everything's through the roof right now. [09:30.780 --> 09:41.780] We're getting to the point where processors couldn't get any faster, so we're going to start dueling up the cores, tripling up the cores, put four cores into a processor just to make things faster. [09:41.920 --> 09:45.360] Now that's going to drive software to become more symmetrically oriented. [09:45.680 --> 09:52.880] So eventually we're going to get to a point where we'll be running 16 2-gigahertz CPUs and the software will actually take advantage of that. [09:53.020 --> 09:53.700] We're not there yet. [09:53.900 --> 09:56.340] So until then, that's what we've got to deal with. [09:56.820 --> 09:57.600] Grid computing. [09:57.760 --> 09:59.120] Sun's big on grid computing. [09:59.300 --> 10:01.840] It's basically a different version of distributed. [10:02.660 --> 10:03.520] Distributed is huge. [10:03.520 --> 10:05.360] Genetic software is software. [10:06.460 --> 10:19.760] When brute forcing, what they're doing now is they're developing a little more smarter brute forcers to where they'll genetically alter what they're guessing just to see if they can statistically hit the target quicker. [10:21.000 --> 10:28.020] We now have, as in the words of Mr. Stallman, we have GNU and GNU plus Linux, so that's cool. [10:28.380 --> 10:32.660] And then Windows XP and Vista is just never going to come out, so, you know, never mind about that. [10:32.920 --> 10:36.400] The other thing, for you Windows users, this is what you need to say. [10:36.620 --> 10:40.480] I'm sorry, Mr. Stallman, please forgive me for using proprietary software. [10:44.810 --> 10:48.750] The Sun Grid is basically a dollar an hour per CPU. [10:48.890 --> 10:52.170] You can buy 10,000 CPUs for one hour at 10,000 bucks. [10:52.410 --> 10:56.850] And that's a lot of horsepower, but it's not available to masses because I don't have $10,000. [10:57.270 --> 10:58.290] I can't do that. [10:58.290 --> 11:02.710] So, it's good for big business, but not good for the little guy. [11:03.150 --> 11:05.610] Distributed computing is basically... [11:06.110 --> 11:12.490] You can have 150-week machines or 100-week machines, but it's heavily dependent on the software. [11:12.630 --> 11:16.810] If your software isn't distributed, then you can't take advantage of that. [11:16.950 --> 11:19.290] And there's not a lot of distributed software out there right now. [11:20.630 --> 11:22.290] This is where time memory trade-off... [11:23.290 --> 11:25.370] Time memory trade-off is an old idea. [11:25.550 --> 11:26.650] It's not new at all. [11:26.650 --> 11:38.950] The preconception was held back basically by the times and the age that it was thought of because you can't do a huge hash database on a 500-gig or a 5-gig hard drive. [11:39.070 --> 11:40.070] It's just not going to work. [11:40.250 --> 11:45.930] You don't have the available memory to trade-off for the time that you want. [11:47.570 --> 11:51.790] Basically, what it is, is store everything the first time for a quick recall later. [11:51.970 --> 11:53.250] That's just the basics. [11:53.410 --> 11:54.010] That's how it is. [11:54.010 --> 11:56.330] It usually consumes huge amounts of memory. [11:56.490 --> 11:59.930] Like I said, we're up to 1.8 terabytes on a single database. [12:00.430 --> 12:04.450] And, I mean, we can scale all the way up to 3, 4, 5, 6, 7, no problem. [12:04.650 --> 12:13.350] Because once you pass that 6-character marker of storing all combinations, especially alphanumeric, you're going to just exponentially increase the size of your database. [12:13.350 --> 12:16.930] So, I could have a 200-gigabyte 1-6 character. [12:17.310 --> 12:22.130] But then, the moment I put that 7 in there, it's going to go up to 1.2 terabytes. [12:22.450 --> 12:24.390] That's the type of exponential increase we get. [12:25.750 --> 12:27.970] Just to give you an idea, you've got to know your key space. [12:28.270 --> 12:35.230] For instance, if you're going to store all 1-6 alpha lower, which is A through all Zs or whatever, you've got to raise it all out. [12:35.230 --> 12:38.390] That's 231 million combinations. [12:38.770 --> 12:41.350] And then, as you see, 1 through 7, you're up in the billions. [12:41.770 --> 12:45.630] And then, 1 through 8, you're 217 billion combinations. [12:45.810 --> 12:47.270] And that's what we're working on right now. [12:47.990 --> 12:50.110] I'll be done with this database in about a month. [12:53.320 --> 12:55.460] The storage requirements, let me just go over. [12:55.600 --> 13:03.120] This is just a little brief of exactly what goes into, you know, what you have to figure out before you can even start thinking about building a database. [13:03.240 --> 13:03.940] Because what are you going to do? [13:03.940 --> 13:08.560] You're just going to code some apps and, you know, buy a couple big hard drives and expect it to fit. [13:08.700 --> 13:09.500] That's not going to happen. [13:10.060 --> 13:16.340] So, in order to store the text in the hash, you've got to figure out what your text is going to cost you in memory and what the hash is going to cost you in memory. [13:16.600 --> 13:21.340] So, if you're looking at it right now, for instance, a 6-character password is going to cost you 3 bytes. [13:21.520 --> 13:24.480] And then, you've got to store the hash next to it. [13:24.660 --> 13:29.000] So, it's going to cost you 19 bytes just to store one line or one password. [13:32.030 --> 13:38.090] If you look at it right now, this is just a good example of the increase in size when you start moving into the next ramps. [13:38.230 --> 13:41.730] For instance, 1-6 alpha lower is only about 5 gigabytes. [13:42.350 --> 13:44.990] The 1-7 alpha lower is about 128. [13:45.370 --> 13:51.070] The 1-8, you're up in the 3.5 terabyte range, which not a lot of people can get to. [13:52.210 --> 13:53.710] Here's what a database looks like. [13:53.810 --> 13:58.050] This is not exactly what ours looks like right now, but this is what the old version looked like. [13:58.290 --> 14:00.890] Basically, you take the text, and you store it next to the hash. [14:01.170 --> 14:02.970] Take the text, you store it next to the hash. [14:02.970 --> 14:05.930] These are the rows in your database. [14:06.570 --> 14:07.390] What you do is... [14:07.390 --> 14:12.090] Let's say I want to search for that hash, the OCC 1-7. [14:12.430 --> 14:17.790] What I'm going to do is make a query to that database, and it's going to match up my hash and it's going to return the text row. [14:18.370 --> 14:22.150] And that's basically... I'm going to get A from it, and that's basically what it is. [14:26.200 --> 14:29.320] Our database is storing exactly what I just showed you. [14:29.460 --> 14:31.760] You store the text next to the hash, it consumes tons of space. [14:31.900 --> 14:32.840] I'm going to drill that. [14:32.980 --> 14:34.800] It consumes tons of space. [14:34.800 --> 14:41.360] The good thing about it is that hash databases have 100% accuracy for their set character set. [14:42.020 --> 14:48.860] If I want to do a hash database on 1 through 7 alpha, I'll have 100% of those passwords in there. [14:49.140 --> 14:56.000] Rainbow tables, if I build rainbow tables for 1 through 6 alpha, I could be missing statistically 5, 7, 8%. [14:56.000 --> 15:03.740] When you're talking billions of passwords, that is literally maybe hundreds of millions of passwords that are not in the database. [15:03.740 --> 15:07.020] That is one of the fallacies of rainbow tables right now. [15:10.010 --> 15:11.610] How many of you have heard of rainbow tables? [15:11.770 --> 15:13.590] Yep, everybody's heard of them, obviously. [15:14.590 --> 15:15.410] Here's the question. [15:15.710 --> 15:17.090] How many of you know how they work? [15:20.330 --> 15:21.110] Brief example. [15:22.810 --> 15:25.550] Computes a value and looks it up depending on what it's based on. [15:25.790 --> 15:26.130] Okay. [15:26.390 --> 15:29.670] Computes a value and looks it up based on what it's... what was it? [15:29.890 --> 15:30.250] Computes a value. [15:30.270 --> 15:31.750] I mean, it functions differently. [15:31.990 --> 15:33.450] Generally, it would be a B5 comparison. [15:33.450 --> 15:34.070] Yeah. [15:34.890 --> 15:39.590] It's... it basically... it's... what a lot of people tell me, I ask them, well, how do rainbow tables work? [15:39.630 --> 15:41.310] And they say, oh, well, they break passwords. [15:41.610 --> 15:42.530] And I said, no, no, no. [15:42.730 --> 15:44.790] What's the mathematics behind rainbow tables? [15:44.910 --> 15:46.030] How does it really work? [15:46.190 --> 15:51.210] And it took me so long to figure out, you know, where did this idea come from, rainbow tables? [15:51.450 --> 15:53.750] It's a really weird name and what is all this stuff? [15:53.750 --> 15:56.970] And so I did a ton of research on it. [15:57.190 --> 16:00.450] And what is it... it builds and stores rainbow chains. [16:00.610 --> 16:02.590] Rainbow chains are basically patterns intervals. [16:03.090 --> 16:05.930] If you want me to elaborate on this, I can. [16:06.030 --> 16:06.510] Do you want me to? [16:06.750 --> 16:07.110] Please. [16:07.350 --> 16:07.550] Okay. [16:07.850 --> 16:08.290] All right. [16:09.810 --> 16:15.490] Basically, what it is, is they take random data, they locate patterns, and then remove all the other data to make intervals. [16:15.910 --> 16:16.150] All right. [16:16.470 --> 16:18.290] There's a string of numbers in front of you. [16:18.290 --> 16:21.190] I need you to find an interval in there. [16:22.430 --> 16:23.690] I'll give you a few seconds. [16:29.820 --> 16:30.960] Five-digit interval. [16:31.200 --> 16:32.380] 0, 5, 10, 15. [16:32.640 --> 16:33.140] Real simple. [16:34.260 --> 16:35.160] There's another one. [16:35.300 --> 16:36.100] 1, 3, 5. [16:36.320 --> 16:37.720] That's a two-digit interval. [16:40.640 --> 16:46.960] The reason they're called rainbow mathematics is because it also has to do with intervals and patterns. [16:47.460 --> 16:51.240] Take that same string of numbers and apply colors to it. [16:51.820 --> 16:54.340] That's where they get the name rainbow tables. [16:54.700 --> 16:58.660] Because now, find an interval or find me a pattern. [16:59.360 --> 17:00.420] Patterns would be colors. [17:00.660 --> 17:01.600] Intervals would be numbers. [17:01.780 --> 17:02.540] I'll give you a few seconds. [17:07.120 --> 17:14.180] Same two intervals, but then you've got a 0 through 16 pattern, which is blue, and a 1, 7, and 14, which would be the light red. [17:14.840 --> 17:17.120] Do you see where the patterns come from, where the intervals come from? [17:17.760 --> 17:19.080] Basically, this is rainbow mathematics. [17:19.800 --> 17:22.720] And what they do is they take these numbers and they wrap them in a circle. [17:23.200 --> 17:32.260] And then, literally, you can go 0, you can go 0, 16, 0, 16, 0, 16, 0, 16, because they're in a circular motion. [17:32.500 --> 17:34.940] And that's where rainbow mathematics basically came from. [17:36.500 --> 17:40.020] The intervals are stored in sequence, along with the same data to help recover it. [17:40.080 --> 17:44.000] There's a little bit of extra bits that they put in there for the reversing of the hashes. [17:44.000 --> 17:48.820] And for the desired result, let's say I want to make a request to the database. [17:48.980 --> 17:51.920] It's 1, 2, 5, 9, 10, 11, and 15. [17:52.400 --> 17:59.340] If I have an interval stored in the database of 1, 5, 10, and 15, how do you think I determine the rest of my desired result? [18:02.650 --> 18:03.510] Yep, that's it. [18:04.110 --> 18:06.310] You brute force the data in between deductively. [18:06.490 --> 18:10.210] What they do is they take 1, 5, 10, 15, and they fill it all up. [18:10.210 --> 18:15.390] And then they say... they remove numbers such as 4, 9, and 14. [18:15.650 --> 18:17.350] And then they say, well, that doesn't match. [18:17.570 --> 18:22.650] Let's put those back and deductively remove more and more and more numbers until we finally get the 1. [18:22.770 --> 18:31.230] This is why rainbow tables can... you can build a huge rainbow table with 99% accuracy and you can make a password to it and it'll take it like that. [18:31.310 --> 18:31.730] It'll do it. [18:31.830 --> 18:35.550] Or you take another password and you go to make a query to it and it'll take 10 minutes. [18:35.730 --> 18:42.690] The reason that it takes that long is because it has to deductively remove all the other numbers to figure out what's the exact result. [18:43.330 --> 18:49.930] Here's some comparisons between the hash database is what I do and the rainbow tables is what the other technique is. [18:50.650 --> 18:56.270] 100% accuracy with the hash database and you have variable accuracy with the rainbow tables. [18:56.750 --> 19:05.250] The storage computations for them, rainbow tables, are obviously a lot smaller because they remove all those unnecessary numbers and store just patterns. [19:05.250 --> 19:07.970] But that also... you also lose time on that. [19:08.150 --> 19:10.670] So you're saving memory but you're losing time on that. [19:10.830 --> 19:13.150] That's where your time memory trade-off balance comes in. [19:13.850 --> 19:21.870] We've developed a technique of applying some really cool CRC mathematics to the whole deal to really figure out... you know, we really shrunk them down a lot. [19:22.250 --> 19:29.130] The other thing is the MD5 lookup has a set search time. [19:29.130 --> 19:36.510] So, if I do a query, it's only going to take me half a second, a quarter of a second, or, you know, three or four seconds to make a query. [19:37.230 --> 19:39.010] Usually, it depends on the size of the database. [19:39.250 --> 19:41.270] Right now, we're running one to one and a half seconds. [19:41.550 --> 19:45.090] And that is basically a delay of the web. [19:45.210 --> 19:46.470] It has nothing to do with the database. [19:46.690 --> 19:52.670] If I'm at the database server itself and I make a query, it's the same result time every time. [19:52.830 --> 19:58.510] If I'm running rainbow tables, it's going to take anywhere from three seconds to ten minutes to do it. [19:58.510 --> 20:00.830] That's the variance I was talking about earlier. [20:02.190 --> 20:04.430] The essence of TMTO... I'm going to drill this again. [20:04.590 --> 20:06.590] All you're doing is you're giving up memory for time. [20:06.770 --> 20:08.190] What's your most valuable asset? [20:09.210 --> 20:09.710] Time. [20:10.190 --> 20:14.390] Because you only have from now to when you die. [20:14.630 --> 20:17.150] And that's your most valuable asset. [20:17.370 --> 20:24.390] So, I'm very willing to give up ten terabytes of space for simply, you know, being able to crack a password in under a second. [20:25.230 --> 20:32.510] Instead of searching the entire key space each time, just go ahead and just generate all the possibilities, store them for quick recall later. [20:32.730 --> 20:33.530] There are a couple of techniques. [20:33.770 --> 20:35.530] These are the hash database rainbow tables. [20:35.750 --> 20:38.950] And then the database are flat file oriented. [20:39.230 --> 20:42.130] This is just basically... you can use a SQL database to store them. [20:42.270 --> 20:44.790] You can use a text file, put them in there in binary. [20:45.950 --> 20:46.830] Basic stuff. [20:47.010 --> 20:47.550] Not a big deal. [20:48.670 --> 20:49.190] All right. [20:49.270 --> 20:51.450] I'm going to go ahead and demo some stuff for you guys. [20:54.850 --> 20:55.650] All right. [20:55.850 --> 21:01.210] I need... give me five passwords, seven long, alpha. [21:01.830 --> 21:02.530] Anybody? [21:02.890 --> 21:03.110] You? [21:03.850 --> 21:07.110] Just seven random characters so that it's not biased at all. [21:08.070 --> 21:08.770] A1... [21:08.770 --> 21:10.590] Just alpha in the seven range. [21:11.090 --> 21:12.970] Lower alpha in the seven range. [21:15.070 --> 21:16.110] A1, W... [21:18.590 --> 21:19.550] Just alpha. [21:19.810 --> 21:20.430] Just letters. [21:20.610 --> 21:20.710] Yep. [21:20.850 --> 21:21.550] Lower letters. [21:21.890 --> 21:26.530] A, C, F, G, Z, one. [21:27.770 --> 21:28.390] All right. [21:28.950 --> 21:30.210] L is going to be the replacement. [21:30.370 --> 21:30.550] All right. [21:30.670 --> 21:31.250] Give me another one. [21:41.610 --> 21:42.970] All right. [21:44.910 --> 21:52.490] A, D, R, G, H, W, S, seven. [21:53.190 --> 21:54.370] All right. [21:55.630 --> 22:00.410] Basically, there's your hashes for the ones that they gave me. [22:00.410 --> 22:04.890] What I'm going to do is go ahead and give you a demo on what MD5 Lookup can do. [22:08.010 --> 22:09.190] Let's take the first one. [22:09.350 --> 22:10.710] A, C, F, G, Z, L. [22:11.190 --> 22:12.310] And I'll go ahead and put this in here. [22:12.790 --> 22:13.050] All right. [22:13.130 --> 22:13.310] Ready? [22:16.050 --> 22:17.730] This is delay on the web, mostly. [22:18.290 --> 22:18.490] Boom. [22:19.870 --> 22:21.630] That's a six-character password broke. [22:22.570 --> 22:23.570] Let's do the next one. [22:28.140 --> 22:29.260] Let's put that in there. [22:33.500 --> 22:34.400] Oh, look. [22:34.400 --> 22:36.080] Another six-character broke. [22:36.600 --> 22:38.580] Let's put the seven in there and see what happens. [22:43.170 --> 22:43.650] Oops. [22:50.360 --> 22:54.800] Notice the exact same return time for no matter what the length is for it. [23:05.360 --> 23:09.440] Let me show you the multi-interface, because doesn't it sort of get boring doing one at a time? [23:09.700 --> 23:14.400] I mean, can you imagine going through an entire list of 500 hashes just being proactive? [23:14.400 --> 23:20.480] Let's say you're auditing your web form database, just to make sure everybody's complying with the set policy that you set. [23:20.680 --> 23:25.340] And let's say you have to have seven long and it has to be alphanumeric or something like that. [23:26.520 --> 23:30.280] It'll just get sort of tedious going through that database and auditing all of them. [23:34.080 --> 23:37.380] So what we'll do is take that and I'll add a few more. [23:40.840 --> 23:42.120] And then we'll do all those. [23:42.260 --> 23:47.300] And all I've got to do is take this, put it in here. [23:47.740 --> 23:49.220] How long do you think it's going to take? [23:49.860 --> 23:50.680] Five seconds. [23:51.180 --> 23:57.540] I'm going to give it about 10 to 15 seconds to break five hashes that are basically completely random. [23:57.540 --> 23:59.120] So let's give it a run. [24:00.240 --> 24:00.500] One. [24:00.840 --> 24:01.360] Two. [24:01.940 --> 24:02.320] Three. [24:03.180 --> 24:03.420] Oh. [24:06.150 --> 24:07.190] Is that scary? [24:14.100 --> 24:15.840] No, I know a lot of you guys. [24:16.080 --> 24:18.380] The concept of TMTO isn't too hard. [24:18.560 --> 24:20.420] It's trading time for memory. [24:20.680 --> 24:23.340] There's a lot of information on the site, MD5Lookup. [24:23.560 --> 24:28.500] And a lot of this stuff can be re-explained on there. [24:28.740 --> 24:30.700] I mean, it's very simple. [24:31.620 --> 24:34.520] I mean, that's the epitome of time memory trade-off. [24:34.720 --> 24:38.860] You see, I broke five hashes in like three and a half seconds. [24:39.400 --> 24:40.720] Completely random data. [24:41.000 --> 24:44.680] And my next database has got a completely different character set. [24:45.060 --> 24:50.860] Really scary stuff, especially for people that don't use SALT, that type of thing on their hashes. [24:51.240 --> 24:54.660] Just to give you a little history, I did not start out big at all. [24:54.900 --> 24:58.320] I mean, my first one was a one through four alphanumeric special everything. [24:58.500 --> 24:59.900] I used PHP and MySQL. [24:59.900 --> 25:03.500] It was basically the slowest, most ridiculous thing on the planet. [25:03.820 --> 25:07.620] You're better off just brute forcing a one through four password because it's so much quicker. [25:07.860 --> 25:10.040] So obviously you have to move up in the scales. [25:10.280 --> 25:13.200] So we moved up to... I moved it over to like a one through five. [25:13.560 --> 25:14.600] Still not too impressive. [25:14.860 --> 25:16.820] Couldn't advocate time memory trade-off at that point. [25:16.900 --> 25:19.000] Because it's still not that impressive at all. [25:19.380 --> 25:20.840] We moved through a one through six. [25:21.560 --> 25:22.380] We're getting there. [25:22.580 --> 25:23.700] Not too big of a deal still. [25:24.500 --> 25:29.000] Then we decided that the databases were getting too ungodly huge. [25:29.320 --> 25:32.580] We needed to figure out how we were going to get around it overall. [25:33.000 --> 25:35.280] So we applied the CRC technique to it. [25:35.500 --> 25:38.660] Definitely cut it down probably to about a third of the original size. [25:38.660 --> 25:41.200] And right now we're at the one through seven mixed. [25:42.060 --> 25:42.900] You know what? [25:43.900 --> 25:45.900] Give me a ten digit number. [25:47.440 --> 25:48.480] Zero through nine. [25:49.400 --> 25:49.860] All right. [25:50.680 --> 25:51.900] Here, let's do this. [25:54.060 --> 25:55.480] Your social security number. [26:00.730 --> 26:02.690] Anybody use their phone numbers or password? [26:04.710 --> 26:05.150] No. [26:05.350 --> 26:05.790] No? [26:06.070 --> 26:09.330] That's pretty good because I think it should break it here. [26:09.610 --> 26:10.010] Oh. [26:11.130 --> 26:11.930] That's not cool. [26:16.230 --> 26:17.090] Let's try that. [26:19.310 --> 26:20.730] Yeah, if it's down now it'll be... [26:20.730 --> 26:21.730] I think it's in the multi. [26:22.210 --> 26:22.650] Oh. [26:22.890 --> 26:23.910] It's in the multi that you have. [26:24.070 --> 26:24.370] That's not on. [26:24.670 --> 26:24.930] Yeah. [26:25.650 --> 26:25.790] Hmm. [26:27.750 --> 26:28.190] Yeah. [26:28.490 --> 26:29.050] But it can... [26:29.050 --> 26:31.130] The next revision of the database will definitely... [26:31.130 --> 26:32.890] I mean, it'll break anything like... [26:32.890 --> 26:34.590] It'll break a zero... [26:34.590 --> 26:36.630] A one through ten digit password. [26:36.870 --> 26:39.510] So that's definitely people that use it. [26:40.130 --> 26:45.570] The next one that we're going to use, I'll show you the character set, and you tell me if it's intimidating or not at all. [26:46.690 --> 26:48.150] Recently we moved from... [26:48.150 --> 26:51.090] The build apps used to be in PHP, which is just ungodly slow. [26:51.410 --> 26:58.750] And, you know, I had to force myself to basically learn C, relearn it again just so that we could recode everything and build the databases faster. [26:58.990 --> 27:00.070] It was taking too long. [27:00.070 --> 27:01.510] Here's the next character set. [27:01.670 --> 27:02.070] For any... [27:02.070 --> 27:07.210] One through five, I'll be able to break all 255 characters in the entire ASCII alphabet. [27:07.810 --> 27:11.250] Six through seven, I'll be able to break anything alpha-numeric in under a second. [27:11.610 --> 27:16.410] The eight length, I'll be able to break any eight length alpha lower in the entire... [27:16.410 --> 27:18.490] All out of all of the eight length possibilities. [27:18.750 --> 27:23.690] Then we're going to move and do anything, basically eight through ten numeric. [27:23.810 --> 27:25.750] So we can break zero through ten numeric in all. [27:25.750 --> 27:27.970] It's going to be about 1.5 terabytes. [27:28.230 --> 27:31.630] Everything is basically... it's 320-gig drives rated together. [27:31.810 --> 27:32.690] It's a huge array. [27:33.750 --> 27:37.250] In about two weeks, this will be on... it was supposed to be done like two weeks ago. [27:37.390 --> 27:39.510] We had a couple power failures, stuff like that. [27:39.610 --> 27:41.410] Sort of a satisfying schedule. [27:41.650 --> 27:43.110] It should be done in about a month. [27:43.290 --> 27:48.950] So you guys need to check back in about a month and definitely check out some of the progress we've made so far. [27:50.950 --> 27:52.650] This is just the CRC stuff. [27:52.670 --> 27:55.190] I could go to explain it, but there's stuff on the web. [27:55.190 --> 27:57.730] I need you to look at because it's really sort of complex. [27:58.070 --> 27:59.730] I don't want to waste a lot of your time. [28:00.270 --> 28:02.670] And it's relatively boring stuff. [28:02.830 --> 28:07.530] But for you gearheads who love to get into that sort of stuff, definitely hit the website, take a look at it. [28:07.850 --> 28:11.390] And there's lots of stuff available on MD5Lookup, so take a look. [28:11.770 --> 28:12.710] Just a couple of guys. [28:13.170 --> 28:14.610] Alex, he definitely helped me out. [28:14.710 --> 28:16.910] Elo, Zcux, these guys were testing for me. [28:17.330 --> 28:20.350] Nolak did a ton of storage calculations for me. [28:20.850 --> 28:23.610] And so he definitely helped me out in my early times. [28:23.610 --> 28:25.770] So I like to give them a little credit. [28:26.850 --> 28:28.050] And that's basically it. [28:28.130 --> 28:28.590] Any questions? [28:30.670 --> 28:32.290] Where do we get a copy of your database? [28:34.170 --> 28:36.330] The question was, where do we get a copy of your database? [28:36.630 --> 28:44.290] Well, since I'm a very good fan of free-slash-open-source software, the build utils are available online, just like Rainbow Table stuff. [28:44.510 --> 28:47.170] You can download the apps and build your own tables if you want. [28:47.170 --> 28:50.830] The only problem is you need a lot of space for it, which is not too bad. [28:52.050 --> 28:53.670] It's definitely available on the website. [28:53.870 --> 28:54.890] You can download the apps. [28:55.450 --> 28:56.790] I'm not going to sell the tables. [28:56.810 --> 28:58.110] I'm not going to do anything like that. [28:58.430 --> 29:00.450] I'm not a big fan of that type of thing. [29:01.230 --> 29:04.030] If I could, yeah, when you have your question, would you just come up to the mic, please? [29:07.790 --> 29:09.490] You're saying... I don't think this mic works. [29:09.490 --> 29:10.210] Is this working? [29:10.350 --> 29:10.830] All right, okay. [29:10.870 --> 29:11.410] It does now. [29:11.810 --> 29:12.110] All right. [29:12.830 --> 29:26.590] You're saying that the space necessary for your technique is approaching Rainbow Tables, but I remember seeing a 20-gig Rainbow Table that will handle lowercase, uppercase, numeric, and... [29:26.590 --> 29:27.650] With what type of accuracy? [29:28.210 --> 29:30.690] 99.9, I believe, for up to seven characters. [29:31.410 --> 29:37.210] It's basically, if it's 20 gigs, that's not realistically possible because I've done a ton of research and I've worked with Ansem himself. [29:37.210 --> 29:37.930] So, no. [29:38.390 --> 29:39.310] It might be close. [29:39.310 --> 29:41.250] It may be like a one through seven, but yeah. [29:41.410 --> 29:42.530] It might not be the right algorithm. [29:42.790 --> 29:44.550] Yeah, it may be a different algorithm, too. [29:45.010 --> 29:45.550] Oh, okay. [29:45.690 --> 29:45.870] Right. [29:46.090 --> 29:49.210] Yeah, if it's an LM algorithm, you're basically Rainbow Tables. [29:49.430 --> 29:50.910] LM is the smallest algorithm. [29:51.050 --> 29:52.810] You only have to break up to seven characters. [29:53.010 --> 29:53.370] That's why. [29:53.510 --> 29:55.670] If it was LM, that's why it would be so small. [29:55.790 --> 29:56.050] I see. [29:56.050 --> 30:00.670] If the same Rainbow Tables were made in SHA-1, it's going to be huge compared to... [30:00.670 --> 30:02.570] And that's what we're comparing to. [30:02.690 --> 30:04.870] We're doing MD5, so we compared it to MD5. [30:05.010 --> 30:05.230] I see. [30:05.230 --> 30:12.070] Okay, so for the character set that you're doing, what would be something that's like 99.9 for Rainbow Table? [30:12.350 --> 30:13.750] What's the size of that? [30:14.010 --> 30:18.570] I think if you go to plain text, I think it's plain-text.info. [30:18.570 --> 30:21.730] They have the comparison table to us, and it's like 1.3. [30:21.930 --> 30:22.290] Okay. [30:22.290 --> 30:23.390] And we're at 1.5. [30:23.570 --> 30:23.810] I see. [30:23.850 --> 30:24.530] So we're pretty close. [30:24.650 --> 30:26.470] We're pretty close for the same character set. [30:28.630 --> 30:29.230] Hi there. [30:29.230 --> 30:40.210] So definitely buying a bunch of hard drives is one option, but have you considered using distributed hash tables or redundant distributed hash tables on the Internet to offload some of this database to other people? [30:40.410 --> 30:41.270] Yeah, most definitely. [30:41.450 --> 30:56.070] The problem with that is we can split up the tables, but what you do is, especially when you're in a production environment like MD5Lookup has, I mean, if you look at it right now, this one's been online since July 1, and it's already had 180,000 queries to it, [30:56.190 --> 30:57.410] and it gets about 1,000 a day. [30:57.550 --> 31:00.870] If I split it up, I'm going to definitely put a damper on my reliability. [31:01.210 --> 31:03.910] But in the homegrown environment, most definitely. [31:04.150 --> 31:10.910] If you've got 50 boxes with 100-gig hard drives in them, throw them all together and distribute the whole thing, just you've got to build an interface for it. [31:11.850 --> 31:12.030] So yeah. [31:12.210 --> 31:14.650] So that's the key thing is going for redundancy. [31:14.790 --> 31:16.170] I mean, if you look at things like the BitTorrent protocol. [31:16.170 --> 31:16.670] Yeah, I went for reliability. [31:16.810 --> 31:18.770] That's why I put everything in one big pile. [31:18.950 --> 31:21.050] If you want to spread all the tables out, that's up to you. [31:21.050 --> 31:21.510] Yeah. [31:21.510 --> 31:21.970] Cool, thanks. [31:22.230 --> 31:22.350] Yeah. [31:25.820 --> 31:26.720] Yeah, I was wondering. [31:28.160 --> 31:31.240] All your work here looks like you're using MD5 as the hash. [31:31.380 --> 31:33.200] What if someone doesn't use MD5? [31:34.000 --> 31:36.500] This is the cool thing about the new technique with CRCs. [31:37.060 --> 31:39.780] And this is the reason we went that way. [31:40.780 --> 31:41.580] Not only... [31:41.580 --> 31:48.840] Because we take the first few bytes of the hash, and all hashes are in hacks, and we build a CRC off of that, it'll do any algorithm. [31:49.080 --> 31:50.580] You just have to tweak the tools to do it. [31:50.580 --> 31:54.880] So it can do LM, SHA-1, SHA-256. [31:55.000 --> 32:02.380] And then the cool thing is, regardless of the hash length, so you're moving up to SHA-1 or whatever, it's a 40-bit byte hash. [32:03.460 --> 32:08.060] It's still going to produce the exact same size in the database, regardless of the algorithm. [32:08.240 --> 32:14.780] That's the other competing thing we have with rainbow tables, is that rainbow tables, as the first question was, the tables vary. [32:15.220 --> 32:17.200] Now, in this essence, the tables do not vary. [32:17.200 --> 32:19.920] They're all the same, because of the CRC technique that's applied to them. [32:20.160 --> 32:24.080] Are you going to have lookup tables available for other hashes besides MD5? [32:24.620 --> 32:27.700] That's basically because I funded this entire project myself. [32:28.000 --> 32:33.160] That's the only reason I haven't moved into other algorithms, because of the initial investment to myself. [32:33.840 --> 32:35.220] So, yeah, it's definitely... [32:35.220 --> 32:39.700] If I had the money, I would have every algorithm on the planet, and I definitely have big tables for them. [32:39.980 --> 32:40.420] So... [32:40.420 --> 32:40.640] Thanks. [32:43.540 --> 32:43.980] Donation? [32:44.160 --> 32:45.040] How long... [32:45.040 --> 32:50.180] As a random guess, how long do you think it will be until salted passwords come into the same danger as this? [32:51.660 --> 32:53.880] As of right now, I'm thinking, like... [32:53.880 --> 33:03.180] Because I've heard stories of, you know, five years ago people built huge tables of all of the salted versions, with all the salts, with all the combinations. [33:04.840 --> 33:11.460] Depending on the size of the salt, if it's a two-bite salt or whatever, it's going to cause... [33:11.460 --> 33:17.100] It's going to cause you to duplicate your table, like, maybe six, eight times, what the regular size is if it wasn't salted. [33:17.300 --> 33:20.880] If you've got a six-bite salt, it's going to... [33:20.880 --> 33:22.140] Like, it's going to be huge. [33:22.280 --> 33:23.600] The table is going to be unbearably big. [33:24.060 --> 33:24.460] So... [33:24.460 --> 33:27.840] It's definitely going to come around eventually, but not right now. [33:27.980 --> 33:28.680] It's just not possible. [33:28.840 --> 33:32.140] Just like TMTO wasn't possible 15 years ago, so... [33:32.140 --> 33:38.320] Just wait until you can crack, I guess, a 32-bite alphanumeric hash, basically, again. [33:38.620 --> 33:38.760] Yeah. [33:39.820 --> 33:41.320] Technology is just holding us back. [33:41.420 --> 33:42.280] That's the only thing right now. [33:43.700 --> 33:48.840] How long do you plan on keeping the service open, and how do you plan on dealing with the possible legality issues? [33:51.340 --> 33:55.920] Realistically, legality issues don't apply, because I'm using it as a proactive security tool. [33:56.060 --> 33:57.620] Have any of you ever used L0phtCrack? [33:58.440 --> 33:59.000] All right. [33:59.000 --> 34:05.880] One of the most popular password crackers on the planet, used in every single place I have ever been to. [34:06.060 --> 34:08.260] This is no different except for it's web-oriented. [34:09.480 --> 34:10.740] There are no legal issues. [34:11.660 --> 34:13.760] What people do with it is up to them. [34:14.000 --> 34:19.000] And unless they're going to go after Symantec, they're not going to... you know, they can't come after me, so... [34:20.000 --> 34:23.700] I'm sorry, I walked in a little bit late, so you may have already answered this, but... [34:23.700 --> 34:26.740] Is there any kind of priority on how your table is set up in the database? [34:27.160 --> 34:30.540] Because it seems to me like someone using a password like... [34:30.540 --> 34:33.840] Or most people generally won't use a password like ZZZZ. [34:34.200 --> 34:38.480] Like, do you have that towards the end to kind of make your query a little bit faster? [34:38.600 --> 34:39.400] Does that make sense? [34:39.400 --> 34:45.760] It's... what it is is it's based off of the hash, so if... and then it's CRC'd and then put into the database. [34:46.140 --> 34:48.780] It's... it's... it's indexed, so it doesn't matter. [34:48.940 --> 34:53.300] Because what it does is the index is put into memory, and memory is searched like that. [34:53.560 --> 34:57.660] So the... as far as storing them in priority, I mean... [34:57.660 --> 34:58.420] It wouldn't make a difference for... [34:58.420 --> 34:59.440] It wouldn't make a difference, no. [34:59.540 --> 35:00.800] It's going to be the same every time. [35:08.120 --> 35:26.900] When you're using this CRC technique to reduce the space it takes up, if you're taking a very... if you were to take a very large, long hash and CRC it down in a smaller space, couldn't that create a problem of conflicts if you actually ran out of potential combinations? [35:26.900 --> 35:28.920] Yes, and that's the reason we reduce a lot of our space. [35:29.080 --> 35:30.860] The question is... the question is... [35:30.860 --> 35:35.020] When you take a long hash and you CRC it, what you're doing is you're creating a smaller hash. [35:35.080 --> 35:36.220] Well, wait a second. [35:36.460 --> 35:38.240] What if two different hashes equal the same thing? [35:38.420 --> 35:39.340] This is the beauty of it. [35:39.480 --> 35:45.740] Because now I don't have to make another row, I just put the CRCs next to each other, and then do a little bit of deductive reasoning, just like the tables. [35:45.960 --> 35:46.980] Except for I can do it... [35:46.980 --> 35:49.620] I can do it a lot faster than rainbow tables can. [35:49.780 --> 35:51.560] So it's... it's almost a similar method. [35:51.860 --> 35:54.360] But what you're doing is you're... you're reversing it. [35:54.760 --> 35:55.340] You're... you're gonna... [35:55.340 --> 36:00.020] Let's say I have FFFF is my CRC of a... of a 32-bit hash. [36:00.320 --> 36:04.860] But then ten different things match that same FFFF CRC value. [36:04.860 --> 36:08.000] What happens is those are all grouped onto the same row in the... [36:08.000 --> 36:08.840] in the text database. [36:09.140 --> 36:10.220] And then they're set. [36:10.520 --> 36:14.460] So it's four... four long is the... the CRC for the text. [36:14.660 --> 36:15.400] Then they're reversed. [36:15.880 --> 36:21.740] So it actually saves space because you can group all the similar ones and still be able to reverse them no problem. [36:21.980 --> 36:24.680] But then you're not creating a row for each different value. [36:24.940 --> 36:25.760] See what I'm saying? [36:25.760 --> 36:28.220] Yeah, so it works kind of like a chained hash table? [36:29.880 --> 36:30.320] Um... [36:30.320 --> 36:30.880] It's... [36:30.880 --> 36:31.700] It's... [36:31.700 --> 36:32.240] It's... [36:32.240 --> 36:33.040] No, it's not even... [36:33.040 --> 36:35.180] It's not even close to that... that same mentality. [36:35.400 --> 36:38.680] The... the code definitely is a lot different in the way that it's done. [36:38.860 --> 36:40.520] It's just... it's relatively complex. [36:42.300 --> 36:42.740] So... [36:44.300 --> 36:44.740] Okay. [36:44.960 --> 36:45.160] Thanks. [36:47.860 --> 36:48.640] Anything else? [37:00.450 --> 37:03.390] And if anyone has any questions, they can come talk to me. [37:03.550 --> 37:06.230] And then my email is actually on the MD5 Lookup site. [37:06.630 --> 37:07.110] So... [37:07.110 --> 37:07.890] Thank you. [37:07.890 --> 37:07.950] Thank you. [37:08.230 --> 37:08.710] Thank you.