Moving to Client-Side Hashing for Online Authentication

Enka Blanchard, Xavier Coquand,Ted Selker

SOCIO-TECHNICAL ASPECTS IN SECURITY AND TRUST, STAST 2019(2021)

引用 1|浏览4
暂无评分
摘要
Credential leaks still happen with regular frequency, and show evidence that, despite decades of warnings, password hashing is still not correctly implemented in practice. The common practice today, inherited from previous but obsolete constraints, is to transmit the password in cleartext to the server, where it is hashed and stored. We investigate the advantages and drawbacks of the alternative of hashing clientside, and show that it is present today exclusively on Chinese websites. We also look at ways to implement it on a large scale in the near future.
更多
查看译文
关键词
Hashing, Web standards, Authentication
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要