
Chris and Robert -- Passwords, Identity, and #AppSec
Om avsnittet
Password advice changes as attackers, hardware, and identity standards evolve. Chris and Robert examine how passwords are guessed, cracked, stored, and reused, then compare long-standing habits with updated NIST guidance. They discuss dictionary attacks, hashing, salts, password length, composition rules, password managers, and the risks of knowledge-based questions. The conversation also explores checking proposed passwords against known breach data through Have I Been Pwned and the operational cost of doing that safely. Throughout, they separate user-facing policy from the developer’s responsibility to store and verify credentials correctly. The result is a practical review of why familiar password rules often fail and how modern applications can make authentication both safer and more usable.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Chris Romeo and Robert Hurlbut:
→ Chris Romeo on LinkedIn
→ Robert Hurlbut on LinkedIn
Mentioned in this episode:
→ NIST SP 800-63B
→ OWASP Password Storage Cheat Sheet
→ Troy Hunt
→ Have I Been Pwned
→ Enpass
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Passwords, identity, and application security
01:30 The reality of hundreds of passwords
03:21 Hardware advances and password cracking
05:15 Dictionary attacks
07:34 Hashing and password storage
09:28 Cracking weak hashes
10:48 Knowledge-based questions and social engineering
13:11 Changes in NIST guidance
14:36 Supporting long passwords
16:03 Password managers
17:42 Evaluating password-manager risk
19:17 Retiring forced periodic changes
21:27 Checking passwords against breach data
23:37 Operational cost and implementation choices
26:19 Maximum length and denial-of-service concerns
28:11 Why every password needs a unique salt
29:43 Slow password hashing
31:15 Final recommendations
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.