Feeds

The Great Hash Bakeoff: Infosec bods cook up next-gen crypto

Take a serverful of hash, add salt, hold the rainbow

Using blade systems to cut costs and sharpen efficiencies

Cryptographers are limbering up for a competition aimed at developing a next-generation password hash to create a better means for websites to store users' login credentials.

In total 24 submissions have been made to the Password Hashing Competition. Cryptographers will now test the effectiveness of the two dozen entrants by attempting to break them over the next 12 months or so before the competition closes.

The exercise seeks to identify new password hashing schemes that are suitable for widespread adoption as well as raising the profile of the issue and fighting against bad practices, such as storing passwords in plain text or not salting hashed passwords, as the competition website explains:

The Password Hashing Competition (PHC) is an effort organized to identify new password hashing schemes in order to improve on the state-of-the-art (PBKDF2, scrypt, etc.), and to encourage the use of strong password protection. Applications include for example authentication to web services, PIN authentication on mobile devices, key derivation for full disk encryption, or private keys encryption.

The PHC is being put together by a group of individuals, not an industry-recognised standardisation body. It might be that the competition throws up entrants who later become candidates for a standard but this is far from a given. Experts on the PHC panel include Matthew Green of Johns Hopkins University and Marsh Ray of Microsoft.

The competition is a marathon and not a sprint, explained Per Thorsheim, an independent security consultant and founder of the well regarded Passwords conferences.

"This competition is organised by Jean-Philippe Aumasson, known Swiss cryptographer and author of BLAKE, which was one of five finalists for the NIST SHA-2 competition," Thorsheim told El Reg.

"Submissions were due by 1 April, and now everybody is hard at work attacking all submissions in every way possible. The current timetable says that a winner will be selected in Q2 2015. Until then there will talks, conferences, mailing lists, meetings and whatnot."

One of the two dozens entries for the competition has already created a bit of a buzz on the interwebs. Researchers at New York University have developed a scheme called PolyPassHash for interlinking the representation of password hashes.

The idea is that instead of being able to use a rainbow table of the password hashes of common passwords or brute force tactics to recover passwords, attackers would be faced with the far trickier business of being obliged to crack groups of passwords together to get anywhere.

Hashing algorithms convert information into a shortened "message digest", via a one-way function that ought to make it impossible to recover the original information. Done successfully, the technology should thwart attempts to generate an identical digest from two different blocks of input data.

Hashing techniques are used in digital signatures, verifying that the contents of software downloads have not been tampered with, and many other cryptographic applications. ®

The smart choice: opportunity from uncertainty

More from The Register

next story
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.