This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Password Storage Cheat Sheet

From OWASP
Revision as of 19:03, 21 September 2011 by Jmanico (talk | contribs) (Password Storage Rules)

Jump to: navigation, search

ACTIVE WORK IN PROGRESS AUGUST 2011

Introduction

This article is focused on providing guidance to storing a passwords in order to help prevent password theft.

Password Storage Rules

  1. Use a Modern Hash
    1. SHA
    2. bcrypt
  2. Use a long cryptograpgically random salt
    1. Isolate the salt from the hash
  3. Iterate the hash

OWASP Cheat Sheets Project Homepage