CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Softwares and Software Security
An Indian software vendor ships an update after finding that its application stores customers' passwords as plain text in the database. Which practice best aligns with secure software design for storing passwords?
Passwords should be stored as salted hashes created with a slow hashing algorithm. Hashing is one-way and salting defeats precomputed lookup attacks. Reversible encryption with a co-located key, simple reversal or plain text with access limits all leave passwords exposed after a breach.
- AStore a salted hash produced with a slow hashing algorithmCorrect
- BStore passwords encrypted with one key kept in the same database
- CStore passwords after reversing the character order
- DStore passwords in plain text but restrict database access
Explanation
Passwords should be stored as salted hashes using a deliberately slow algorithm, so they cannot be reversed and precomputed attacks are hindered. Encryption with a key stored alongside the data is reversible and the key is exposed in a breach. Reversing characters is trivial, and access restriction does not protect against a breach.
Did you get it right without looking?
One question tells you little. A timed set on Softwares and Software Security shows your real accuracy, how long you take and where you lose marks.
More Softwares and Software Security questions
- Which feature distinguishes a copyleft open-source licence such as the GNU General Public License from a permissive licence such as MIT?
- A company's web form builds a database query by directly joining user-typed text into the SQL string. Which control is the most effective pr…
- Sharma Textiles uses a licensed accounting package. An employee installs a cracked copy of the same package on a personal computer. Under In…
- A manufacturing firm's staff find that a vendor's software has a serious flaw that is not yet known to the vendor, and attackers are already…
- A disgruntled software engineer at an Indian firm embeds code in the payroll system that will delete salary records if his own employee ID i…
- A fintech firm's developers test a web application by feeding it deliberately malformed and random inputs to see whether it crashes or expos…