6 ms·
"a large database containing more than 30 million Microsoft accounts, emails, and passwords." A database containing passwords? Why would anyone store passwords
by xpil 3y ago
"a large database containing more than 30 million Microsoft accounts, emails, and passwords."
A database containing passwords? Why would anyone store passwords in a database is beyond my comprehension.
- endisneigh 3y agoWhere else should you store the passwords?
- rolph 3y agoon a post-it, under the keyboard its safer there
- _Algernon_ 3y agoNot at all. You store a salt and the hash(pw+salt).
- charcircuit 3y agoBe warned that this makes your authentication system less secure because it caps the maximum entropy of the password to the entropy of the hash function.
- poizan42 3y agoYou need crazy long passwords for that to become the limiting factor. With random printable characters on the keyboard there are a bit less than 7 bits per character (unless a crazy amount of different accents are used). So you need passwords longer than 18 characters to surpass the entropy of even MD5.
- gpvos 3y agoWhat would you suggest instead?
- charcircuit 3y agoA simple change if you don't want to change it too much eg. moving away from passwords would be to use a sponge function instead of a hash and and squeeze out the same number of bits as the plaintext.
- tatersolid 3y agoA cryptographic sponge function has a fixed capacity just like a the fixed state size of a cryptographic hash function…
- charcircuit 3y agoGood point. How about splitting the password into chunks, then use a key streching algorthim on each chunk with difficulty tuned to be easier based off the total amount of chunks, and concatenating them.
- gpvos 3y agoThat sounds like the kind of homebrew crypto that one should never do in production. I'll stick to my boring but proven salted hashes, thanks.
- endisneigh 3y agothat's still "storing the passwords", though. no one said it should be stored in plain text.
- deleted 3y ago[deleted]
- SigmundA 3y agoNo a one-way hash is not "the password". If you have the hash you can't use it to login or reverse it to a password without brute force comparison which is why you always store a hash with salt using slow hashing algo, and not "the password", this has been best practice for years so a DB breach does not mean the password are compromised.
- endisneigh 3y agoI agree, but it's still the password in that it's the secret set of characters needed to be compared against to login. It's just not the same text a user would enter when prompted for the password. Keeps in mind these hackers are the ones saying they have passwords and this is Microsoft. Most likely hashes.
- SigmundA 3y agoI disagree you cannot use the hash to login, therefore it is not a password. Is a digital signature the item it is signing? The whole point of hashing passwords is so if the DB containing them is breached the passwords are not compromised.
- hot_gril 3y agoRight, but if someone mentions passwords in a non-technical context like a random Twitter threat, it's possible they mean the hashes.
- ceejayoz 3y agoIn general, you don't. You store hashes. Exceptions sometimes apply when it's a credential used to access some other system - for example, Plaid's gonna have to store your bank account password to scrape it - but there you'd at least hope for encryption. Media coverage tends not to get the distinction right, so it's always hard to tell if the company fucked up or the attacker is exaggerating on early coverage.
- poizan42 3y agoNobody said the passwords weren't hashed
- ceejayoz 3y agoThe article states "the group provided 100 credential pairs". That indicates one of a couple things; a) lying attacker providing old hacked accounts, b) unsalted or weakly salted credentials vulnerable to rainbow tables or brute force or c) plaintext storage.
- taeric 3y agoIt could also be colloquial use of "credential pairs." In that it could be that they were, in fact, hashed; but the report went with a quick verbiage to say they were leaked. Especially considering that most hashing/encoding tricks will go out of date and many common passwords will still be as effectively leaked.
- DistractionRect 3y agoOr it's just credential stuffing matching email with plaintext passwords from other old breaches, or they created 100 accounts and thus know the password, etc. Until a more detailed investigation/write comes out it's difficult to say for certain what they have, if anything.
- prepend 3y agoHashes aren’t passwords. So if they only have hashes, they don’t have passwords.
- deleted 3y ago[deleted]
- gpvos 3y agoHowever you store them, it is a database. And there's actually nothing wrong with using a relational database for that. (Of course, you don't store passwords, but salts and salted hashes.)
- xpil 3y agoOf course there is nothing wrong with using a relational database. My concern was about storing passwords in it. There is a difference between storing passwords and storing hashes and/or salts.