News

Fake password technology protects data from hackers

Thursday 21 May 2015 00:20 CET | News

A team of researchers has developed a system that makes it harder for hackers to obtain usable passwords from a leaked database.

Dubbed ErsatzPasswords, the system is aimed at throwing off hackers who use methods to ‘crack’ passwords. Passwords are typically encrypted when stored by organisations. The passwords are encrypted using an algorithm, and that output - called a hash - is stored. Hashes are considered safer to store than plain-text passwords.

To do that, hackers use brute-force techniques, which involve creating lists of words that could be possible passwords and computing their hash to see if a match is found. To cut down on that time, hackers use programs, which can draw on large lists of passwords from different data breaches whose hashes have already been calculated. 

ErsatzPasswords adds a new step. Before a password is encrypted, it is run through a hardware-dependent function, such as one generated by a hardware security module. That step adds a characteristic to a password that makes it impossible to restore it to its accurate plain text without access to the module. The result is that if a hacker starts to get matches on a list of hashes, all of the passwords will not work. The hacker would not know that necessarily until he or she tried them to access a service.


Free Headlines in your E-mail

Every day we send out a free e-mail with the most important headlines of the last 24 hours.

Subscribe now

Keywords: cyber-attacks, cyberfraud, web fraud, online security, internet users, cyber-security, passwords
Categories: Fraud & Financial Crime
Companies:
Countries: World
This article is part of category

Fraud & Financial Crime






Industry Events