Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Chris and Robert -- Passwords, Identity, and #AppSec

32 min12 september 2017

Om avsnittet

Password advice changes as attackers, hardware, and identity standards evolve. Chris and Robert examine how passwords are guessed, cracked, stored, and reused, then compare long-standing habits with updated NIST guidance. They discuss dictionary attacks, hashing, salts, password length, composition rules, password managers, and the risks of knowledge-based questions. The conversation also explores checking proposed passwords against known breach data through Have I Been Pwned and the operational cost of doing that safely. Throughout, they separate user-facing policy from the developer’s responsibility to store and verify credentials correctly. The result is a practical review of why familiar password rules often fail and how modern applications can make authentication both safer and more usable.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Chris Romeo and Robert Hurlbut:
Chris Romeo on LinkedIn
Robert Hurlbut on LinkedIn

Mentioned in this episode:
NIST SP 800-63B
OWASP Password Storage Cheat Sheet
Troy Hunt
Have I Been Pwned
Enpass

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Passwords, identity, and application security
01:30 The reality of hundreds of passwords
03:21 Hardware advances and password cracking
05:15 Dictionary attacks
07:34 Hashing and password storage
09:28 Cracking weak hashes
10:48 Knowledge-based questions and social engineering
13:11 Changes in NIST guidance
14:36 Supporting long passwords
16:03 Password managers
17:42 Evaluating password-manager risk
19:17 Retiring forced periodic changes
21:27 Checking passwords against breach data
23:37 Operational cost and implementation choices
26:19 Maximum length and denial-of-service concerns
28:11 Why every password needs a unique salt
29:43 Slow password hashing
31:15 Final recommendations

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.