Moving to client-side hashing for online authentication

dc.contributor.authorBlanchard, Nikola K.
dc.contributor.authorCoquand, Xavier
dc.contributor.authorSelker, Ted
dc.date.accessioned2019-10-23T15:19:44Z
dc.date.available2019-10-23T15:19:44Z
dc.description.abstractCredential leaks still happen with regular frequency, and show evidence that, despite decades of warnings, password hashing is still not correctly implemented in practice. The common practice today, inherited from previous but obsolete constraints, is to transmit the password in cleartext to the server, where it is hashed and stored. We investigate the advantages and drawbacks of the alternative of hashing client-side, and show that it is present today exclusively on Chinese websites. We also look at ways to implement it on a large scale in the near future.en
dc.description.sponsorshipThis work was supported partly by the french PIA project “Lorraine Université d’Excellence”, reference ANR-15-IDEX-04-LUE.en
dc.description.urihttp://koliaza.com/files/Client_Password_Hashing.pdfen
dc.format.extent17 pagesen
dc.genrejournal articlesen
dc.identifierdoi:10.13016/m2yrru-suxe
dc.identifier.citationBlanchard, Nikola K.; Coquand, Xavier; Selker, Ted; Moving to client-side hashing for online authentication; http://koliaza.com/files/Client_Password_Hashing.pdfen
dc.identifier.urihttp://hdl.handle.net/11603/15964
dc.language.isoenen
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Computer Science and Electrical Engineering Department Collection
dc.relation.ispartofUMBC Faculty Collection
dc.rightsThis item is likely protected under Title 17 of the U.S. Copyright Law. Unless on a Creative Commons license, for uses protected by Copyright Law, contact the copyright holder or the author.
dc.subjectHashingen
dc.subjectWeb standardsen
dc.subjectAuthenticationen
dc.titleMoving to client-side hashing for online authenticationen
dc.typeTexten

Files

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
2.56 KB
Format:
Item-specific license agreed upon to submission
Description: