Which of the .NET included hashing algorithms are suitable for password hashing?

后端 未结 3 1908
失恋的感觉
失恋的感觉 2020-12-05 08:29

The password leak of LinkedIn proved how important it is to securely hash your passwords. However, even hashing passwords with a salt is not secure with the \'normal\' hashi

相关标签:
3条回答
  • 2020-12-05 08:51

    I think it's not really a meaningful Class name, but I do think it is included in the .NET framework. According to multiple sources, Rfc2898DeriveBytes is actually a PBKDF2 implementation. MSDN says so as well.

    See Why do I need to use the Rfc2898DeriveBytes class (in .NET) instead of directly using the password as a key or IV? and PBKDF2 implementation in C# with Rfc2898DeriveBytes

    for example.

    0 讨论(0)
  • 2020-12-05 09:04

    There is no hashing algorith that is 100% secure. The linkedin hack was more due to infrastructure/code security than the hashing algorithm. Any hash can be calculated, it just takes longer the more complicated the hashing algortihm is. Some attacks such as collision attacks are not actually much slower to accomplish on a more complicated hash.

    I always ensure that i hash passwords (never just encrypt), restrict access to servers. All developers workingfor me understand at least the basics of security (sql injection, overflows etc) and any high profile site i work on is pen-tested.

    0 讨论(0)
  • 2020-12-05 09:11

    There is also:

    http://bcrypt.codeplex.com/ (bcrypt)

    http://www.zer7.com/software.php?page=cryptsharp (scrypt, etc)

    0 讨论(0)
提交回复
热议问题