You are here >  theory >  storage

Introduction

TOP

Storage and retrieval of passwords is an important aspect of the process of authentication. One might ask: "how is storage and retrieval related to authentication?". Password is used (in combination with login/user name, pin or smart card) for authentication. Hence, if passwords are not stored and retrieved in a secure way, they are not helping the process of authentication. Insecure storage and retrieval could give any user, the privilege to access the stored password. This means that anyone can authenticate as your or me, to sign into our email accounts, websites, database, etc., which is definitely not good for us.

Ways to store and retrieve

TOP

There are several ways to store and retrieve passwords. To simplify this, we would look at it as two different methods based on where it is getting stored:

  • Online Storage
  • Local Storage
  • In each of the above method, there are two forms in which they could be stored:

  • Plain text

  • Cipher text

Plain text is something like what you are reading right now, which is "clear text". Cipher text on the other hand is where, an algorithm is implemented in the form of tools to convert plain text to cipher text. In other words, cipher text is the encrypted password. These days, attackers and crackers in the wild has the most powerful tools and processing power for cracking passwords to gain unauthorized access. That being the case, plain text is ruled out of the option of secure storage. There are couple of protocols that send everything in plain text on the wire/across the network. They are File Transfer Protocol [FTP, uses 21/TCP for command channel] and Telnet (uses 23/TCP). On the other hand, Secure Shell [SSH, uses 22/TCP] uses encrypted channel to transfer packets across the network. Hence, even if you store the password online or on a remote box after encrypting it and if you choose to use an unencrypted channel/protocol to transfer the password on the wire, then you are still in trouble of password being snooped/tapped. This is why storage and retrieval is really important, when it comes to passwords and hence we chose to allocate space and time to discuss on this. More about storage and retrieval [types, tools and techniques] could be found in the "Theory" section of Password Analytics, under "Storage 102".

EvilFingers Arsenal
































Socialize with RootkitAnalytics

Twitter Feed Blogspot

Socialize with EvilFingers

Twitter Feed Blogspot LinkedIn Delicious Google

Tweets


@abbietoeknee Ooh. #evilfingers

#FF @yuridiogenes, @PrivateiAlbert, @dave_rel1k, @j0emccray, @Jabra, @hdmoore, @rodsoto, @cyb3rs3c, @EvilFingers,

Thx to @Sebdraven @EvilFIngers @alisoncdiana and @RickBlaisdell for mentions, #FF, RTs and the kind words

RT @EvilFingers: The Pirate Bay returns, Anonymous hater takes credit for DDoS http://t.co/lToXLoUW

RT @mickmcavoy: Actually this has now trumped my previous intriguing comic book cover! #evilfingers http://t.co/HyuB26Wr

Actually this has now trumped my previous intriguing comic book cover! #evilfingers http://t.co/HyuB26Wr

@EvilFingers Sen Ruppersberger said the same thing about #CISPA. But his focus was on importance of info sharing #UMDCyber

@EvilFingers companies not reqd to clean data they vol give gov #UMDCyber

@EvilFingers companies not reqd to clean data they vol give gov

RT @EvilFingers: Cybersecurity Bill Runs Into Trouble: http://t.co/NdI0YlHF < According 2 Panel @ #UMDCyber on cyberlegislation (cont)

Tweeting Times Release http://t.co/qFIdqEqw - top stories by AnonymousPress, egyp7, EvilFingers

The Cybersecurity Daily is out! http://t.co/Z8G9X7Un ▸ Top stories today via @evilfingers @security_expert @amarshall_asi @anuesystems

Fun with #pcap again https://t.co/maCfpmfr

a k'wala's PrivSec Daily is out! http://t.co/swVv36jO ▸ Top stories today via @evilfingers @kaepora

My Tweeted Times http://t.co/FERk0sHU - top stories by threatpost, suffert, EvilFingers

#FF @yuridiogenes, @PrivateiAlbert, @dave_rel1k, @j0emccray, @Jabra, @hdmoore, @rodsoto, @cyb3rs3c, @EvilFingers

RT @evilfingers: Unrepentant Hippie and World Networker Randy Bush Enters Net’s Hall of Fame: Randy Bush, known for his volunteer......

RT @SecureThinking: @nesitct @zecurion @evilfingers @score4africa - Thanks for the mention, appreciated!

My Tweeted Times http://t.co/YR09QIG3 - top stories by CryptoCoinMedia, PrivacyMemes, EvilFingers

@nesitct @zecurion @evilfingers @score4africa - Thanks for the mention, appreciated!

The NESIT Daily is out! http://t.co/Q4W1RuHO ▸ Top stories today via @zecurion @evilfingers @score4africa @securethinking

top news from security list http://t.co/1RBZYhf6 - top stories by EvilFingers, nicolasbrulez, briankrebs