Moving to client-side hashing for online authentication - Université Paris 8 Vincennes - Saint-Denis Accéder directement au contenu
Communication Dans Un Congrès Année : 2019

Moving to client-side hashing for online authentication

Xavier Coquand
  • Fonction : Auteur
Ted Selker
  • Fonction : Auteur
  • PersonId : 1020025

Résumé

Credential leaks still happen with regular frequency, and show evidence that, despite decades of warnings, password hashing is still not correctly implemented in practice. The common practice today , inherited from previous but obsolete constraints, is to transmit the password in cleartext to the server, where it is hashed and stored. We investigate the advantages and drawbacks of the alternative of hashing client-side, and show that it is present today exclusively on Chinese web-sites. We also look at ways to implement it on a large scale in the near future.
Fichier principal
Vignette du fichier
blanchard-2019-movingclientsided.pdf (523.53 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-02560695 , version 1 (02-05-2020)

Identifiants

  • HAL Id : hal-02560695 , version 1

Citer

Enka Blanchard, Xavier Coquand, Ted Selker. Moving to client-side hashing for online authentication. 9th International Workshop on Socio-Technical Aspects in SecuriTy, Sep 2019, Luxembourg Ville, Luxembourg. ⟨hal-02560695⟩
146 Consultations
349 Téléchargements

Partager

Gmail Facebook X LinkedIn More