EPISODE · Sep 12, 2017 · 32 MIN
Chris and Robert -- Passwords, Identity, and #AppSec
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Password advice changes as attackers, hardware, and identity standards evolve. Chris and Robert examine how passwords are guessed, cracked, stored, and reused, then compare long-standing habits with updated NIST guidance. They discuss dictionary attacks, hashing, salts, password length, composition rules, password managers, and the risks of knowledge-based questions. The conversation also explores checking proposed passwords against known breach data through Have I Been Pwned and the operational cost of doing that safely. Throughout, they separate user-facing policy from the developer’s responsibility to store and verify credentials correctly. The result is a practical review of why familiar password rules often fail and how modern applications can make authentication both safer and more usable.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Chris Romeo and Robert Hurlbut:→ Chris Romeo on LinkedIn→ Robert Hurlbut on LinkedInMentioned in this episode:→ NIST SP 800-63B→ OWASP Password Storage Cheat Sheet→ Troy Hunt→ Have I Been Pwned→ EnpassFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Passwords, identity, and application security01:30 The reality of hundreds of passwords03:21 Hardware advances and password cracking05:15 Dictionary attacks07:34 Hashing and password storage09:28 Cracking weak hashes10:48 Knowledge-based questions and social engineering13:11 Changes in NIST guidance14:36 Supporting long passwords16:03 Password managers17:42 Evaluating password-manager risk19:17 Retiring forced periodic changes21:27 Checking passwords against breach data23:37 Operational cost and implementation choices26:19 Maximum length and denial-of-service concerns28:11 Why every password needs a unique salt29:43 Slow password hashing31:15 Final recommendations
Embed this episode
What this episode covers
Password advice changes as attackers, hardware, and identity standards evolve. Chris and Robert examine how passwords are guessed, cracked, stored, and reused, then compare long-standing habits with updated NIST guidance. They discuss dictionary attacks, hashing, salts, password length, composition rules, password managers, and the risks of knowledge-based questions. The conversation also explores checking proposed passwords against known breach data through Have I Been Pwned and the operatio...
Ready to play
Chris and Robert -- Passwords, Identity, and #AppSec
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.