3 ms·
Nonetheless you must admit it is possible. If I did this, that's how I'd do it. Have a separate computer, locked down to the max, except for a couple of functi
by sailormoon 17y ago
Nonetheless you must admit it is possible.
If I did this, that's how I'd do it. Have a separate computer, locked down to the max, except for a couple of functions: accepting HTTP requests POSTing an encrypted password, then sending back the decrypted string. That function would be severely rate-limited. Another function, to confirm the hash of passwords, would not be rate-limited, allowing high volumes of website access.
I could make that machine friggin' impregnable (and so could you). But yeah. No-one ever does it.
- tptacek 17y agoI wouldn't do it at all. If I wanted escrowed access to a VM, I'd stick a "break glass" SSH key on the box. I'm not sure how "extremely secure" this "password-decrypting server" design really is, by the way. SQLI is often equivalent to remote code execution. Even when it isn't, XSS is equivalent to operator access, and operators can use the feature that decrypts the password. Passwords are hazmat. You shouldn't be storing them, at all.
- sailormoon 17y agoYeah. I used to disagree with you, but now I agree. You should write up a definitive guide for password security. For instance, I want to know if we should still use salts in the age of bcrypt, etc. Tell us what to do, man.
- tptacek 17y agoI kind of don't want to be "the password guy".
- sailormoon 17y agoHaha. I understand.
- Nwallins 17y agoUm, sounds like an industry standard HSM http://en.wikipedia.org/wiki/Hardware_Security_Module http://en.wikipedia.org/wiki/Hardware_Security_Module