Don't encrypt passwords

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
2,885
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Jan 11, 2012

Encryption passwords is bad. Try hashing them with a little bit of salt on top. Confused about the terminology - maybe i can clear your confusion with the use of a shoe, a box and a pen & paper.

Don't forget to like the video if its been of any use to you.
As always, I'm easy to stalk.

www.J4vv4D.com
Facebook.com/J4vv4D
twitter: @J4vv4D
youtube.com/infoseccynic

Link to this comment:

Share to:

Uploader Comments (InfosecCynic)

  • Hey bud u can easily rebuild a sha or dmd5 with a rainbow table!. ur a cissp?

  • @theoriginalfatdonkey yes, you can, hence the addition of the salt. I learnt all of that in my CISSP (not really)

see all

All Comments (12)

Sign In or Sign Up now to post a comment!
  • ok buddy, salt is only a method of encrypting weak sha's, u got it!

  • haha "old and busted, shiny hotness"... nice MIB II reference. haha great vid, I always used md5 instead of sha. Is that okay?

  • Nice Analogy. Thanks for putting this together.

  • @tdmfhk1 You issue them a new one

  • We learnt all about salted base64 encryption at Shmoocon, ask Kevin Johnson for more info :)

  • Good Vid. One thing though, I wouldn't recommend using SHA-1/2/256 really for password hashing. A better bet would be bcrypt or scrpyt or PBKDF2 all of which are specifically designed for passwords.

  • @tdmfhk1 Sucks to be him?

  • Very "clever" and if the user forget his password?

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more