Chris and Robert -- Passwords, Identity, and #AppSec episode artwork

EPISODE · Sep 12, 2017 · 32 MIN

Chris and Robert -- Passwords, Identity, and #AppSec

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Password advice changes as attackers, hardware, and identity standards evolve. Chris and Robert examine how passwords are guessed, cracked, stored, and reused, then compare long-standing habits with updated NIST guidance. They discuss dictionary attacks, hashing, salts, password length, composition rules, password managers, and the risks of knowledge-based questions. The conversation also explores checking proposed passwords against known breach data through Have I Been Pwned and the operational cost of doing that safely. Throughout, they separate user-facing policy from the developer’s responsibility to store and verify credentials correctly. The result is a practical review of why familiar password rules often fail and how modern applications can make authentication both safer and more usable.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Chris Romeo and Robert Hurlbut:→ Chris Romeo on LinkedIn→ Robert Hurlbut on LinkedInMentioned in this episode:→ NIST SP 800-63B→ OWASP Password Storage Cheat Sheet→ Troy Hunt→ Have I Been Pwned→ EnpassFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Passwords, identity, and application security01:30 The reality of hundreds of passwords03:21 Hardware advances and password cracking05:15 Dictionary attacks07:34 Hashing and password storage09:28 Cracking weak hashes10:48 Knowledge-based questions and social engineering13:11 Changes in NIST guidance14:36 Supporting long passwords16:03 Password managers17:42 Evaluating password-manager risk19:17 Retiring forced periodic changes21:27 Checking passwords against breach data23:37 Operational cost and implementation choices26:19 Maximum length and denial-of-service concerns28:11 Why every password needs a unique salt29:43 Slow password hashing31:15 Final recommendations

Episode metadata supplied by the publisher feed · Published Sep 12, 2017

Embed this episode

Password advice changes as attackers, hardware, and identity standards evolve. Chris and Robert examine how passwords are guessed, cracked, stored, and reused, then compare long-standing habits with updated NIST guidance. They discuss dictionary attacks, hashing, salts, password length, composition rules, password managers, and the risks of knowledge-based questions. The conversation also explores checking proposed passwords against known breach data through Have I Been Pwned and the operatio...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Chris and Robert -- Passwords, Identity, and #AppSec

0:00 32:06

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 32 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 12, 2017.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!