Re: Hashed PW's more secure than encrypted PW's?

From: Mike Delaney (mdelan@computer.org)
Date: 06/14/02


From: Mike Delaney <mdelan@computer.org>
Date: Fri, 14 Jun 2002 14:36:37 -0500

On Fri, 14 Jun 2002 19:13:30 GMT in <ufrO8.34200$nZ3.6595@rwcrnsc53>,
sakhalinrf@hotmail.com said something similar to:
:
: So it seems to me that hashing the passwords is no more secure than just
: encrypting the passwords. In either case, it seems to me that the level of
: security would boil down to, in the case of encryption, the length of the
: key, and in the case of hashing, the length of the password. Yet all the
: literature I have read has emphatically stated that hashing the passwords is
: better than encrypting them. What am I missing here?

The fact that in order to encrypt rather than hash the passwords, the
key itself has to be stored somewhere. Find the key, and you can
decrypt the passwords.

-- 
Mike Delaney <mdelan@computer.org>
"...Microsoft follows standards.  In much the same manner that fish follow 
migrating caribou." "Now I have this image in my mind of a fish embracing and
extending a caribou." -- Paul Tomblin and Christian Bauernfeind in the SDM 



Relevant Pages

  • Re: Hashed PWs more secure than encrypted PWs?
    ... : encrypting the passwords. ... key, and in the case of hashing, the length of the password. ... : better than encrypting them. ...
    (comp.security.unix)
  • Re: how to hide oracle instance name within dbi code??
    ... See for example the way Mozilla stores passwords ... If the program is used non-interactively, encrypting ... putting them into configuration files still makes a lot of sense: ... That's the environment of the process itself. ...
    (perl.dbi.users)
  • Re: Are Active Directory passwords encrypted?
    ... Just want to verify that passwords are automatically encrypted in Active Directory and on the domain controllers. ... What happens when you connect to a file is you basically acquire a service ticket at the DC by encrypting a message from the DC with your hashed password. ... The DC verifies the encrypted answer and - if the password is correct - hands out a ticket for the file server service. ...
    (microsoft.public.windows.server.active_directory)
  • Re: password encode and decode ?
    ... These passwords are encrypted when being written ... to the database and have nothing to do with encrypting passwords between the ... client browser and the server. ... As both the database and PHP are server-side, ...
    (comp.lang.php)
  • Re: creating a key from a password
    ... > keys from passwords. ... I figured I could use md5 or sha on the password ... > for encrypting files with blowfish so since i already have the bf alg ... authenticate the message (encryption without authentication is often ...
    (sci.crypt)

Quantcast