Rock Salt: A Method for Securely Storing and Utilizing Password Validation Data

BSidesLV 2016

Presented by: Arnold Reinhold
Date: Tuesday August 02, 2016
Time: 14:00 - 14:50
Location: Tuscany
Track: Passwords

Rock Saltâ„¢ is a method for storing and accessing password verification data on multi-user computer systems that resists remote attacks. Along with commonly- employed measures that limit the number of unsuccessful attempts to login or otherwise verify a password, it allows users to choose relatively simple passwords with full security. The secret component cannot be easily leaked or exfiltrated by malware, does not require periodic backup and is isolated in a way that allows it to be protected by conventional security measures, such as safes, alarm systems and video surveillance, from attackers who somehow gain access to the computing facility.

Arnold Reinhold

Arnold Reinhold has been involved with password and passphrase security since the mid-1990s. He is the developer of Diceware, CipherSaber and HEKS, the first password hash designed to consume memory resources as well as CPU time. He has worked on spacecraft navigation at NASA, apparel industry automation at Marcon, computer-aided design software at Computervision Corp. and helped found Automatix Inc., an early robotics and machine vision company. Mr. Reinhold is co-author of several For Dummies books, including The Internet For Dummies Quick Reference and Email For Dummies, and contributes regularly to Wikipedia. Mr. Reinhold studied mathematics at MIT and management at Harvard.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats