Method to Protect Passwords in Databases for Web Applications.

Scott Contini · 2015

Trying to make it more difficult to hack passwords has a long history [3, 14, 20, 16]. However the research commu-nity has not addressed the change of context from traditional Unix mainframe systems to web applications which face new threats (DoS) and have fewer constraints (client-side com-putation is allowed). In absence of updated guidance, a variety of solutions are scattered all over the web, from am-ateur to somewhat professional. However, even the best ref-erences have issues such as incomplete details, misuse of ter-minology, assertion of requirements that are not adequately justified, and too many options presented to the developer, opening the door to potential mistakes. The purpose of this research note is to present a solution with complete details and a concise summary of the requirements, and to pro-vide a solution that developers can readily implement with confidence, assuming that the solution is endorsed by the research community. The proposed solution involves client-side processing of a heavy computation in combination with a server-side hash computation. It follows a similar approach to a few other proposals on the web, but is more complete and justified than any that we found. 1.

Read the paper · More papers on PaperTik