6 ms·
What legitimate use case is there for implementing a 2-way encryption method over a hash function for passwords?
by sigden 11y ago
What legitimate use case is there for implementing a 2-way encryption method over a hash function for passwords?
- ryanlol 11y agoCustomer support. A human can then verify the user even if they can only remember a part of the password.
- stephenr 11y agoSounds like a security flaw ripe for social engineering
- ryanlol 11y agoCustomer support by itself tends to be a security flaw ripe for social engineering.
- stephenr 11y agoPhone support can be tricky yes, but there are other ways to identify the caller without storing their password in plaintext
- ryanlol 11y agoCallbacks? Users PII? There's really no good ways to do phone verification. You can't use any kind of shared secrets as people forget those.
- stephenr 11y agoMy bank uses an automated system to verify a pin (ie the operator transfers you to confirm identity then you come back) But it also depends on the realm. Before the saas craze, a lot more support was performed in-house meaning you didn't have the same scale of problem.
- ryanlol 11y agoVerify a pin? But that's still something you have to remember, not providing support for users who have forgotten their passwords doesn't tend to be an option.
- stephenr 11y agoAs I said, it's for my bank, so it's my card pin - I already need to remember it. Also as I said - this was much less of an issue when companies maintained IT departments and installed software. It's much easier to verify that Julie on the phone really is Julie when it's an internal support mechanism.
- paulhauggis 11y agoI never said it was the best method to use over a hash function. However, it's much better than plain text and it would be unethical to say the company didn't have any security of the original poster doesn't know for sure.