Passwords & hash functions (Simply Explained) Simply Explained https://www.youtube.com/watch?v=cczlpiiu42M Transkript (automatisch erstellt) 0:00 You might have found out that there is a website that checks if your online accounts have been compromised by hackers. 0:06 So you enter in your email address and OH NO… You have been pwned! 0:10 Hackers now know the passwords that you used on all these services… But do they really know your password? 0:17 Well as it turns out: that might not be the case... To understand why, let’s take a look at what options companies have to protect your 0:25 password and safely store it so that even when hackers get access to their systems, your password stays safe. 0:32 There are 3 ways a company can store your password: they store it in plain text, use encryption on it or use what’s called a hash function. 0:41 Let’s quickly go over each one of these and let’s start with the most basic one: plain text. 0:46 This is obviously the most dangerous way of storing passwords. If hackers breach a company’s database, they get to see all the passwords of the users. 0:55 And since a lot of people have the bad habit of using the same password for multiple accounts, it’s likely that 1 compromised password could lead to more compromised accounts. 1:06 You might think that companies aren’t silly and that none of them stores our passwords in plain text. 1:11 However you would be very wrong in thinking that. Past breaches have showed us that even top companies and services with millions of users 1:17 weren’t adequately protecting user passwords. One possible alternative to plain text storage is encryption. 1:25 Take the passwords of the users and - before your store them - encrypt them with an encryption key. 1:31 This would prevent hackers from obtaining the real passwords of users but it’s still quite risky. 1:36 Underneath the encryption layer is still a plain text password and so if the attacker manages to steal the encryption key as well, he can unlock all passwords. 1:46 Encryption is designed to work in two ways: you can encrypt a user’s passwords to keep it safe but you can also decrypt it to reveal the password again. 1:55 This is very practical when you want to share data in a secure way, but nog great if you want to prevent attackers from breaching your password. 2:04 And that brings us to the third technique of storing passwords and that is by using a hash function. 2:10 How does that work? Well hash functions take an input, that could be a piece of text like your password or it 2:15 could be a file and turns that into a string of text that always has the same length. There are many different hash functions available but here is what the SHA3 hash of “Hello 2:26 World!” looks like: 2:28 Hash functions are very different from encryption because they only work in 1-way. You can calculate the hash of a password but you cannot take a hash and turn it back into 2:37 the original data. And that’s an interesting property to have. 2:42 By using hashes, companies can verify that you’re logging in with the correct password, without having to store your actual password. 2:49 You can compare hashes to fingerprints. You can take the fingerprint of any person BUT if you find a fingerprint somewhere you 2:51 can’t identify the person it belongs to, unless you’ve seen that print before! However they aren’t perfect either. 2:53 Most hashing algorithms are optimized for speed, the more hashes per second they can calculate, the better. 2:58 And that makes them vulnerable against brute-force attacks. By simply trying to calculate every possible password, an attacker can reverse the hash 3:08 function. A modern GPU can do this with a speed of 292 million hashes per second (292.2 MH/s) so 3:14 it’s only a matter of time before a hashed password is cracked using this technique. And if that’s not fast enough, attackers can also use Rainbow tables to further accelerate 3:24 the process. These are lists of precomputed hashes that can be used to quickly find weak and commonly 3:30 used passwords. The speed of hashing functions are a positive thing in certain area’s. 3:36 However when it comes to storing passwords you don’t want this property. The second problem happens when users share the same password. 3:46 If both Alice and Bob have the password “qwerty”, the hashes of their passwords will be identical. So when a hacker cracks of these passwords, he also knows the others. 3:57 Now you might think: that’s not a big deal because it’s very unlikely that different people will use the same password. 4:02 Well think again. The password “qwerty” has been found more then 3 million times in data breachers. 4:09 To make matters even worse: here’s the top 10 most used password in 2017… Not the strongest of passwords… 4:17 To defend against these attacks we can add what’s called a salt to the password before we hash it. 4:23 The salt is just some random data but it ensures that the hash of your password will always be unique, even if others are using the same password. 4:32 So if Bob and Alice both use the password “qwerty” their hashes will be completely different. 4:38 So if an attacker cracks Bob’s password, he can’t link that password to Alice and he has to start his cracking attempt again. 4:46 This technique prevents attackers from cracking a bunch of passwords in 1 go. It makes a brute force attack slower, but still very much possible. 4:55 So to solve this, we have to take a look at the third technique, which is using special hash functions that are deliberately being slowed down. 5:04 Example of these are bcrypt, scrypt or argon2 and they completely neutralise brute force attacks. 5:10 These algorithms take a password as input along with a salt and a cost. This last one is very interesting: the cost defines the number of rounds the algorithm 5:20 goes through and this effectively slows it down. Over time our computers become faster and so brute force attacks against these algorithms 5:29 becomes easier. That’s because they can simply try more combinations in shorter timespan. 5:34 All we have to do to counter this is increase the cost parameter so the algorithm remains resistant against these attacks. 5:42 Pretty genius! So that are the 3 options that a company has to store and protect your passwords. 5:49 But why settle for just one method if we can use multiple? You can’t be greedy enough when it comes to security! 5:56 This multi-layer protection is used by Dropbox for instance. They take your password and start by running it through a simple hash function, no salt. 6:04 This is their first line of defense. They then take the hash and run it through the bcrypt algorithm with a salt and a cost 6:11 of 10. This prevents brute-force attacks. 6:14 And finally the resulting hash is encrypted with the Advanced Encryption Standard or AES. The encryption key for this is not stored in their databases but is instead kept separately. 6:26 So if an attackers breach the Dropbox database they will have to peel away each protective layer around your password and that will take a lot of time. 6:35 In fact, the cracking attempt would like be more costly then what they’d in return for comprising your account. 6:42 So time for a conclusion then: if you’re account has been compromised, its best to change your password immediately. 6:49 However depending on the security measures of the company that was compromised, it might be possible that hackers haven’t been able to retrieve your password. 6:57 That’s thanks to the magic of hash function and cryptography in general. So now you know how companies can safely store your passwords. 7:06 That was it for this video. If you learned something from it: hit the thumbs up button and consider getting subscribed. 7:12 And as always: thank you very much for watching!