SSCP Systems Security Certified PractitionerSystems and Application SecurityMedium
A security team is evaluating a legacy application for potential vulnerabilities. They discover that the application stores user passwords directly in a database column without any form of cryptographic protection. Which cryptographic technique is the most appropriate and secure method for storing passwords in a database?
- AUsing a simple MD5 hash for password storage.
- BEncoding the passwords using Base64.
- CHashing the passwords with a strong, salted, adaptive hashing function.
- DEncrypting the passwords using AES-256.
Show answer & explanationAnswer & explanation
Correct answer: C. Hashing the passwords with a strong, salted, adaptive hashing function.
Passwords should never be encrypted (as they would need to be decrypted, exposing the key) or simply encoded. Hashing with a strong, salted, and adaptive function (like bcrypt, scrypt, or Argon2) is the industry standard. Salting prevents rainbow table attacks, and adaptive functions (with work factors) make brute-forcing computationally expensive.
Why the other options are wrong
- A. MD5 is a cryptographically broken hashing algorithm, vulnerable to collision attacks and too fast for secure password hashing.
- B. Base64 encoding is not a cryptographic protection; it's reversible and offers no security.
- D. Encrypting passwords means they can be decrypted, making them vulnerable if the encryption key is compromised.
Secure Password Storage
The practice of storing user passwords in a way that prevents them from being easily recovered or used by attackers, even if the storage system is compromised.
- Never store passwords in plaintext or encrypted form.
- Always use strong, one-way hashing algorithms.
- Passwords must be 'salted' to prevent rainbow table attacks.
- Use adaptive (slow) hashing functions (e.g., bcrypt, scrypt, Argon2).
Memory trick: Store passwords like precious jewels, not in plain sight.