Skip to content
  • `To be a member of the hashpwn community, you must read and follow all forum rules.` Repeated violations of these rules will result in a ban.

    5 6
    5 Topics
    6 Posts
    cycloneC
    Terms of Service & Privacy Policy Effective Date: Aug 31, 2025 Welcome to hashpwn.net (“we,” “our,” or “us”). By accessing or using hashpwn.net or any of its subdomains (collectively, the “Services”), you agree to comply with and be bound by these Terms of Service. This includes, but is not limited to, the forum and any Services we may provide under the hashpwn.net domain. If you do not agree, please discontinue use of the Services. 1. Eligibility You must be at least 18 years old to register for or use any hashpwn.net Services. By using our Services, you represent that you meet this requirement. 2. User Conduct When using any hashpwn.net Service, you agree not to: Post, share, or request personally identifiable information (PII). Share, request, or distribute illegally obtained data (e.g., combo lists, stolen data, etc). Engage in hate speech, harassment, or unlawful activities. Attempt to compromise, disrupt, or misuse any Service we provide. Post, share, request, or link to any sexually explicit, pornographic, or sexually suggestive content. Our Services are intended for ethical cybersecurity research, discussion, and learning. Illegal activity is strictly prohibited. 3. User Content You retain ownership of any content you post, upload, or submit to hashpwn.net Services. By submitting content, you grant hashpwn.net a non-exclusive, worldwide license to store, display, and distribute your content as necessary to operate and provide the Services. Requests for deletion of publicly posted content will be honored, except in rare cases where retention is required for legal, security, moderation, or administrative reasons (e.g., evidence of abuse). Account deletion and personal data removal requests will always be honored. 4. Privacy & Data Collection We respect your privacy. We collect basic technical information such as IP address, cookies, browser type, and usage analytics. We use this information only for site functionality, security, and moderation. We may log usage data to maintain service quality. We do not sell, rent, or share your information with third parties for advertising or marketing purposes. Users may request removal of their personal data. 5. Disclaimer of Warranties All Services provided by hashpwn.net are offered “as is” and without warranties of any kind, whether express or implied. We do not guarantee uptime, availability, or error-free operation for any Service. Use of hashpwn.net Services is at your own risk. 6. Limitation of Liability To the fullest extent permitted by law, hashpwn.net, its owners, administrators, moderators, and affiliates are not liable for any damages arising from use of our Services, including but not limited to loss of data, downtime, security issues, or service interruptions. 7. Termination We reserve the right to suspend, restrict, or terminate accounts or access to any hashpwn.net Service at our discretion for violations of these Terms or other reasons deemed necessary to protect the community and infrastructure. 8. Changes to the Terms We may update these Terms at any time. Changes will be posted on this page with a new effective date. Continued use of our Services after updates are posted constitutes acceptance of the revised Terms. 9. Contact For questions, concerns, or requests, please contact: @cyclone (Admin/Owner)
  • This section is dedicated to paid offers, services, and opportunities. Please adhere strictly to the forum rules when posting. All transactions and discussions must maintain a professional tone, and any violation of guidelines will result in penalties. Read the rules carefully before participating.
    https://forum.hashpwn.net/category/1/forum-rules-must-read

    `You will need to be granted access status to participate in the Paid Section.`

    13 20
    13 Topics
    20 Posts
    No new posts.
  • 52 Topics
    379 Posts
    cycloneC
    @tuman has been temp banned (7 days) for hijacking other user's threads 3x times after being warned to stop. Read the rules, or get banned. https://forum.hashpwn.net/post/31
  • General discussions that don't fit in other categories. All topics must still follow forum rules.

    22 202
    22 Topics
    202 Posts
    freerouteF
    Is a Duress Password Legal? The GrapheneOS Border Case [image: 1785493938873-is-a-duress-password-legal-grapheneos-border-case.png] Short answer: yes, having one is legal. Using one is where the risk starts. No law bans a duress password. The software that offers the feature is legal to build, legal to publish, and legal to install. But a US traveler is now facing a federal charge because his phone allegedly erased itself in front of border officers who were about to seize it, and the government’s theory is that typing a passcode you set months earlier still counts as destroying property to stop a seizure. That is a genuinely new legal question. It is also, for almost everyone reading this, the wrong thing to worry about. Our guide to phone and laptop seizures at airports and borders opens with the fantasy most people carry through customs: “When shit hits the fan, I will just wipe all data off my device in front of the border agents.” This case is what that sentence looks like when someone actually does it. What a duress password actually does A duress password is a second unlock credential that destroys the device instead of opening it. GrapheneOS, the hardened Android build for Pixel hardware, documents it plainly: entering the duress PIN or password anywhere the system asks for your credentials “will irreversibly wipe the device (along with any installed eSIMs).” Three properties matter. It is silent. There is no confirmation prompt, no countdown, no way to take it back. The screen goes dark and restarts. It is total. The wipe destroys the encryption key material, so the data is not deleted in a recoverable sense. It is mathematically gone, and the project has said publicly that there is nothing they can do to help anyone recover it. It has a trap. If you set the duress credential to the same value as your real unlock, the real unlock wins and no wipe happens. GrapheneOS documents that too, and it is the kind of detail people miss when they configure a feature they hope never to use. What happened at Hartsfield-Jackson On January 24, 2025, Samuel Tunick, an Atlanta resident, landed at Hartsfield-Jackson on his way home from abroad. Customs and Border Protection pulled him into secondary inspection and pressed him to unlock his Google Pixel. According to reporting by TechCrunch, officers told him no warrant was needed because he had not yet crossed the border. He entered a passcode. The screen went blank, the phone restarted, and its contents were inaccessible. Officers seized the device and let him into the country. Roughly eighteen months later, prosecutors charged him under 18 U.S.C. § 2232, the federal offence of destroying property to prevent a government seizure. The indictment says he “did knowingly destroy, damage, waste, dispose of, and otherwise take any action to delete the digital contents of a Google Pixel cellular phone, for the purpose of preventing and impairing the Government’s lawful authority.” He has pleaded not guilty. The maximum sentence is five years. His defense argues the stop and the seizure were unlawful, that he was repeatedly refused access to a lawyer, and that the government was investigating his association with an Atlanta environmental protest movement rather than any crime. A ruling on the motion to suppress is not expected before late October 2026. Everything above is allegation and argument. Nothing has been proven either way, and this article takes no position on whether he did what the government says. Why the charge, not the search, is the story Warrantless border device searches are old news. What is new is the theory attached to this one. Section 2232 prosecutions are extraordinarily rare. Tunick’s public defender has said only one other case of this kind is publicly known, and it came out of a drug trafficking investigation. Applying it here means a court has to decide whether a preconfigured operating system feature, triggered by typing a string into a prompt, is the same kind of act as smashing a hard drive on a table. If the answer is yes, then a setting becomes an offence at the moment you use it. That is the part worth watching, whatever happens to this defendant. Your rights at the border are getting thinner, not thicker The legal ground moved in the same month the case became public, and it did not move your way. On July 13, 2026, the Fourth Circuit ruled in United States v. Belmonte Cardozo that a manual search of a phone at the border is a routine search, so officers need no warrant and no suspicion at all to scroll through it by hand. As the EFF explains, the court kept a higher bar for forensic extraction, which still requires individualized suspicion in that circuit, but drew the line so that a human thumbing through your messages counts as ordinary. Other circuits disagree, and similar cases are pending elsewhere. The compelled-passcode question under the Fifth Amendment is separately unresolved, with courts split on whether making you type your own passcode is testimony. The practical result is that your rights at an airport depend on which airport it is, and on a body of law that is actively changing. You cannot plan around that. You can only reduce what is at stake when it goes against you. What GrapheneOS said, and what it pointed at The project’s response was unambiguous on the law. It called the feature completely legal, said it has no obligation to weaken the protections it ships, and argued that being forced to do so would be unconstitutional. Then it did something more interesting. Asked about the case, GrapheneOS mostly talked about everything except the duress password, calling it “only one component” of the security model and listing what actually does the work: hardware-backed encryption with rate limiting enforced by the secure element support for passwords up to 128 characters automatic reboot back to the Before First Unlock state after a set period, 18 hours by default, adjustable from 10 minutes to 72 hours USB set to charging-only while the device is locked, which is the shipped default memory tagging and other exploit mitigations against extraction tooling Read that list again. Not one of those requires you to do anything at the counter. They are all already running while you stand in line, exhausted, being asked questions by someone with far more power in that room than you have. That is the whole argument, and the project made it without quite saying it. Passive protection beats active destruction [image: 1785493608645-screenshot-2026-07-31-at-12-25-44-is-a-duress-password-legal-the-grapheneos-border-case-privacytools.io.png] The top three cost you nothing and are invisible. The bottom one is the only row on this table that has ever turned a bad afternoon into a prosecution. A phone in Before First Unlock has never been unlocked since boot. Its keys are not in memory. It is the strongest state your device can be in, forensically, and reaching it costs one long-press before you join the queue. So should you set a duress password? This is not legal advice, and if you are in a situation where this question is live for you, the person to ask is a lawyer in your jurisdiction, before you fly rather than after. With that said, an honest read: If you already travel clean, it adds risk without adding protection. A device carrying nothing sensitive has nothing to destroy. You get the entire benefit of a wipe by simply not bringing the data, and none of the exposure. Its real use case is coercion with no legal process at all. Robbery, kidnapping, a hostile actor with no warrant to seek and no court to answer to. In that scenario the calculus is completely different, and the feature is doing exactly what it was designed for. The failure modes are worse than people expect. It is irreversible. It takes your eSIMs with it, which can leave you with no connectivity in a foreign country. Muscle memory under stress is unreliable, and the wrong finger on the wrong digit at the wrong moment ends the same way whether you meant it or not. Having it set is not the same as using it. Nothing in this case suggests that configuring the feature is itself a problem. The alleged act was entering it after officers demanded access. What to do instead Do not bring the data. This is the whole game, and it is covered properly in the border seizure guide. Everything else on this list is a rounding error next to it. Reboot before you reach the desk. One long-press puts the phone in Before First Unlock, which is free, invisible, and asks nothing of you later. Shorten the auto-reboot window. If a device is seized while locked, a 30-minute timer means it locks itself down hard long before anyone gets it to a lab. Leave USB on charging-only when locked. A plugged-in phone should not be able to talk to anything. Use a password, not your face. The Fifth Amendment picture for memorized passcodes is contested but real. For biometrics it is considerably weaker, and a fingerprint can be taken from you without your cooperation. If you run a hardened Android build as your daily driver, the same logic applies more sharply, not less. Read the full-disk encryption guide for what encryption at rest does and does not cover, and see our mobile operating systems picks if you are choosing a platform. The lesson The technical protections in a modern hardened phone are genuinely excellent. Against thieves, against remote attackers, against ordinary forensic tooling, they hold up. What they cannot do is fix a legal problem. And the feature that gets the most attention, the one that promises you a way out at the last second, is the only one that asks you to make an irreversible decision at the worst possible moment, in front of the person you are trying to stop. Privacy that depends on you performing correctly while frightened, jet-lagged and outnumbered is not a plan. It is a bet. The protections worth having are the ones already in place before you walk up to the desk, which is why the right time to think about any of this is when you build your threat model, not when someone asks for your phone.
  • Discuss useful tools related to hash cracking. Do not upload binaries or post links to malicious files.
    Follow Posting Template:
    https://forum.hashpwn.net/post/68

    56 239
    56 Topics
    239 Posts
    cycloneC
    v0.5.3; 2026-07-25 https://github.com/cyclone-github/pcfg-go/releases/tag/v0.5.3 pcfg_guesser ~2× faster than v0.5.2 ~2,578% faster than Python3 pcfg_guesser.py Reduce long-run RAM growth in pcfg_guesser (priority-queue frontier) Compact parse-tree representation (interned type IDs, packed nodes, arena reuse) Contiguous index-based heap (fewer per-item allocations) Reuse OMEN optimizer cache per worker Prefer []byte guess building to cut string churn Same generation logic; parallel stdout interleaving may differ across runs Rename trainer to pcfg_trainer
  • A collection of hashcat rules, wordlists, useful links to online services, and other resources related to hash cracking and password recovery.
    Follow Posting Template:
    https://forum.hashpwn.net/post/68

    32 14k
    32 Topics
    14k Posts
    hashpwn-botH
    Escrow ID# 90653 • Algorithm: RAR5, -m 13000 • Total hashes: 1 • Price per hash: $0.0200 • Escrow URL: https://hashes.com/en/escrow/item/?id=90653 • Download hashes: 90653_13000.zip
  • Forum announcements, comments and feedback.

    5 35
    5 Topics
    35 Posts
    cycloneC
    Scheduled Host Maintenance Our host will be performing scheduled maintenance that requires a reboot of the VPS hosting hashpwn. During this maintenance, the forum and related hashpwn services will go offline temporarily. Expected downtime is less than 30 minutes, although we have not been given an exact ETA for when the reboot will occur. This notice is just to give everyone a heads up.