EC-Council Certified Ethical Hacker (CEH) v12CryptographyEasy
A system administrator needs to securely store user passwords in a database. To protect against rainbow table attacks and ensure that identical passwords result in different stored hashes, which cryptographic technique should be employed in conjunction with a strong hashing algorithm?
- AKey stretching
- BDigital signatures
- CEncryption with a symmetric key
- DSalting
Show answer & explanationAnswer & explanation
Correct answer: D. Salting
Salting involves adding a unique, random string to each password before hashing. This ensures that even if two users have the same password, their stored hashes will be different, effectively defeating rainbow table attacks which rely on precomputed hashes.
Why the other options are wrong
- A. Key stretching increases the computational cost of guessing a password, but doesn't prevent rainbow tables for identical passwords without salting.
- B. Digital signatures provide authenticity and non-repudiation, not protection for stored passwords.
- C. Encryption is for confidentiality, not for securely storing hashes or preventing rainbow table attacks.
Salting
Salting is the process of adding a unique, random string (salt) to a password before hashing it. This technique makes rainbow table attacks ineffective and ensures that identical passwords produce different hash values.
- Defeats rainbow table attacks.
- Makes each password hash unique.
- Salt is stored alongside the hash, often in plain text.
Memory trick: Salty stretching makes password hashes strong and unique.