4 ms·
Note that password hashes are used for more than just password database; they are also used for key derivation functions, for example for deriving a key for enc
by lambda 13y ago
Note that password hashes are used for more than just password database; they are also used for key derivation functions, for example for deriving a key for encrypting a hard drive or document from a password that someone types in. Any full-disk encryption system needs to use a password based key derivation function for security, and your security if the disk is stolen is solely based on the strength of your password and the strength of your key derivation function (unless you have tamper-proof hardware that is able to store your key and only allows interactive authentication, rather than reading the key out and brute-forcing the password out of it).
In fact, encrypting files using a key derivation function was the original use for scrypt, not storing password databased.
> In general, strong password encryption is only useful to prevent bad public relations from too many users getting hacked at one time.
It's also good for lowering the value of cracking your system. If everyone (or a large fraction of developers) does it, it lowers the expected value of breaking into a random system that has low-value accounts. Since people frequently reuse passwords, stealing the password database for a low-value system and cracking them can be used for breaking into higher value systems, as you can try reusing the username or email and password pairs for logging into other systems.
- peterwwillis 13y agoIt doesn't matter what you use it for. Encrypted passwords are simply not a strong enough single factor to prevent a successful attack. If you use FDE you should also be using a keyfob, thumb drive, etc. There's too many attacks on passwords alone, for example the most effective one, where the police compel you to reveal it. (Compelling you to reveal the location of a keyfob is arguably more difficult for them to do) To be honest, I find it completely useless to hypothesize about why someone would attack a system, much less for something as silly as shared passwords. It's much less work to just attack the one account on the one system than to attack two completely different systems on the hope that the password is shared. And botherding/phishing to compromise accounts is much more simple & effective than trying to compromise a password database.
- lambda 13y ago> It doesn't matter what you use it for. Encrypted passwords are simply not a strong enough single factor to prevent a successful attack. If you use FDE you should also be using a keyfob, thumb drive, etc. There's too many attacks on passwords alone, for example the most effective one, where the police compel you to reveal it. (Compelling you to reveal the location of a keyfob is arguably more difficult for them to do) Security is not an absolute. There are plenty of attacks where a strong password & strong key derivation function for FDE will prevent many possible attacks. It helps plug the improperly erased discarded hard drives hole, the thief on the train who steals your laptop opportunistically looks through your data for anything valuable. Yes, two factor is better, but it increases the complexity; and for many cases in which you want FDE, such as a laptop while travelling, there are far too many times where you keyfob and laptop will both be accessible to an attacker, thus negating the benefit of the separate factors. It's better to have a good password and good KDF for FDE than it is to forgo FDE altogether. > To be honest, I find it completely useless to hypothesize about why someone would attack a system, much less for something as silly as shared passwords. It's much less work to just attack the one account on the one system than to attack two completely different systems on the hope that the password is shared. And botherding/phishing to compromise accounts is much more simple & effective than trying to compromise a password database. No, on an industry-wide scale it is not useless to hypothesize about motivations. If you decrease the expected value of an attack, you decrease the motivation for people to break into systems. Getting credit card numbers and easily cracked passwords out of databases that are accessible to front-end systems does a lot to help reduce the expected value of attacks, and thus reduce people's motivation to perform them in the first place. Thus, recommendations for security should keep that in mind. If you make good, easy to implement recommendations for security, that help reduce the value of a successful attack, you can improve global security. For example, token based systems can help avoid credit cards being stolen; instead of each merchant storing CC numbers, if they store tokens that are only valid for them talking to their CC processor, then there's no valuable trove of CC numbers to be found by exploiting the database. There's this really dangerous meme going around that if security isn't absolute it's worthless. That can be true if you assume a highly motivated attacker with government level resources at their disposal who is targeting you specifically, but that's not the attacker that actually causes most people problems. Instead, it's some bored Eastern European kid who doesn't have much in the way of job prospects and wants to make a quick buck, and figures that trying out some basic SQL inject exploits against a large number of sites will be likely to lead to some valuable information. If enough people remove that valuable information from their site or make it difficult enough to extract the contents by using good key derivation functions, there's less economic incentive to try that kind of wide-scale probing attack. This is part of the principle of defense in depth. You are absolutely right, you should secure your password database so that it can't be stolen, and you should protect passwords in flight so that they can't be sniffed. But you should also have good, hard to break password encryption, so that even if you made a mistake and are vulnerable at that outer layer, your users are still protected from having their passwords revealed to attackers. Likewise, you should have both a firewall, and intrusion detection systems that live behind your firewall, and strong authentication and encryption for all services behind that firewall so that even if someone circumvents the firewall, they still can't get into any of your systems. So yes. Prevent your password database from being stolen. Use strong passwords. Don't reuse passwords between sites. But also, use strong password hashing that's hard to crack so that your users are still secure even if all of the above suggestions fail.