SSCP Systems Security Certified PractitionerCryptographyEasy

A system administrator needs to implement a secure method for storing user passwords in a database. The solution must make it computationally expensive for an attacker to crack passwords even if the hashed password database is stolen. Which cryptographic technique is specifically designed to achieve this goal?

  1. AStoring passwords in plaintext with access controls
  2. BEmploying a password-based key derivation function (PBKDF)
  3. CEncrypting the database with AES-256
  4. DUsing a simple hash function like MD5
Show answer & explanation

Correct answer: B. Employing a password-based key derivation function (PBKDF)

Password-based Key Derivation Functions (PBKDFs) like PBKDF2, Bcrypt, or Scrypt are designed to be computationally intensive, making brute-force and rainbow table attacks against stolen password hashes much more difficult and time-consuming. They also incorporate salting to prevent pre-computation attacks.

Why the other options are wrong

  • A. Storing passwords in plaintext is a severe security vulnerability and never an acceptable practice.
  • C. Encrypting the database protects against unauthorized access to the database itself, but once decrypted, the passwords (or their hashes) could still be vulnerable if the hashing isn't robust.
  • D. MD5 is cryptographically broken and completely unsuitable for password storage due to its speed and known vulnerabilities.

Password-Based Key Derivation Function (PBKDF)

A function that derives cryptographic keys from a password or passphrase, designed to be computationally expensive to deter brute-force attacks.

  • Makes password cracking computationally intensive.
  • Incorporates salting to prevent rainbow table attacks.
  • Examples include PBKDF2, Bcrypt, Scrypt.

Memory trick: PBKDF Protects Passwords.

More Cryptography questions