Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
Premium Land with House for Sale
anil1961
Updated:
Yesterday at 10:15 AM
AWS Certified Solutions Architect-Associate + AWS Certified Cloud Practitioner
Sanjeewani95
Updated:
Wednesday at 8:16 PM
🚀 එක පැකේජ් එකයි - මාසෙටම Unlimited Internet! 🌐
sayuru bandara
Updated:
Tuesday at 10:57 AM
🎬 CapCut Pro 1 Month Access! LKR 600
sayuru bandara
Updated:
Tuesday at 10:55 AM
🚀 Google One AI PRO Plan (Gemini Pro Activation) – 18 Months Access! LKR 2200
sayuru bandara
Updated:
Tuesday at 10:53 AM
Electronics
Vehicles
Property
Search
Reply to thread
Forums
General
ElaKiri Talk!
🔴 PayHere වැඩ පෙන්නයි! 65GB ක දත්ත ලීක් කරගනී!
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="Edward Kenway" data-source="post: 27666619" data-attributes="member: 522682"><p>Who on earth use the same salt for every password? if that's the case then why would they store the salt with hash? It'll be rows upon rows of same value wouldn't it??</p><p></p><p>Well the problem with using HSM is two fold. </p><p></p><p>1) Encrypting passwords is unnecessary and unethical. Encryption is used when you intend to get the original value later. With a password that's not needed and it's wrong to know your users password. Encryption is less secure because it has to facilitate reversing whatever it does. Hashes are not. </p><p></p><p>This is what OWASP has to say about the matter. </p><p></p><p></p><p></p><p><a href="https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html" target="_blank">https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html</a></p><p></p><p>2) More you access your HSM, larger the attack surface is. if you store passwords in HSM that means you need to access it every time user logs in. Unnecessary action that can jeopardise the security of items that you actually need to store in the HSM.</p></blockquote><p></p>
[QUOTE="Edward Kenway, post: 27666619, member: 522682"] Who on earth use the same salt for every password? if that's the case then why would they store the salt with hash? It'll be rows upon rows of same value wouldn't it?? Well the problem with using HSM is two fold. 1) Encrypting passwords is unnecessary and unethical. Encryption is used when you intend to get the original value later. With a password that's not needed and it's wrong to know your users password. Encryption is less secure because it has to facilitate reversing whatever it does. Hashes are not. This is what OWASP has to say about the matter. [URL]https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html[/URL] 2) More you access your HSM, larger the attack surface is. if you store passwords in HSM that means you need to access it every time user logs in. Unnecessary action that can jeopardise the security of items that you actually need to store in the HSM. [/QUOTE]
Insert quotes…
Verification
Dahaya deken beduwama keeyada?
Post reply
Top
Bottom