SSCP Systems Security Certified PractitionerCryptographyEasy
A large enterprise is designing a new internal application that requires strong user authentication. They want to implement a system where user passwords are never stored in plain text and are difficult to reverse engineer, even if the database is compromised. Which cryptographic technique is BEST suited for this requirement?
- ADigital signatures
- BAsymmetric encryption
- CHashing with a salt
- DSymmetric encryption
Show answer & explanationAnswer & explanation
Correct answer: C. Hashing with a salt
Hashing with a salt is the standard and most effective method for storing user passwords. Hashing transforms the password into a fixed-size string, making it irreversible, and the salt prevents rainbow table attacks and ensures identical passwords hash to different values.
Why the other options are wrong
- A. Digital signatures provide integrity and non-repudiation for data, not secure storage of passwords.
- B. Asymmetric encryption is also reversible and generally too complex and slow for password storage.
- D. Symmetric encryption is reversible, meaning passwords could be decrypted if the key is compromised.
Password Hashing with Salt
A cryptographic technique for securely storing passwords by transforming them into irreversible hash values, combined with a unique, random string (salt) for each password.
- Protects against rainbow table attacks.
- Ensures two identical passwords yield different hash values.
- Makes brute-force attacks more computationally intensive.
Memory trick: Passwords: Hash it, Salt it, Secure it!