Preprint Open Access

[Preprint] Evaluation of Password Hashing Schemes in Open Source Web Platforms

Ntantogian Christoforos; Malliaros Stefanos; Xenakis Christos


Citation Style Language JSON Export

{
  "publisher": "Zenodo", 
  "DOI": "10.5281/zenodo.2633020", 
  "title": "[Preprint] Evaluation of Password Hashing Schemes in Open Source Web Platforms", 
  "issued": {
    "date-parts": [
      [
        2019, 
        4, 
        8
      ]
    ]
  }, 
  "abstract": "<p>Nowadays, the majority of web platforms in the Internet originate either from CMS to easily deploy websites or by web applications frameworks that allow developers to design and implement web applications. Considering the fact that CMS are intended to be plug and play solutions and their main aim is to allow even non-developers to deploy websites, we argue that the default hashing schemes are not modified when deployed in the Internet. Also, recent studies suggest that even developers do not use appropriate hash functions to protect passwords, since they may not have adequate security expertise. Therefore, the default settings of CMS and web applications frameworks play an important role in the security of password storage. This paper evaluates the default hashing schemes of popular CMS and web application frameworks. First, we formulate the cost time of password guessing attacks and next we investigate the default hashing schemes of popular CMS and web applications frameworks. We also apply our framework to perform a comparative analysis of the cost time between the various CMS and web application frameworks. Finally, considering that intensive hash functions consume computational resources, we analyze hashing schemes from a different perspective. That is, we investigate if it is feasible and under what conditions to perform slow rate denial of service attacks from concurrent login attempts. Through our study we have derived a set of critical observations. The conjecture is that that the security status of the hashing schemes calls for changes with new security recommendations and updates to the default security settings.</p>", 
  "author": [
    {
      "family": "Ntantogian Christoforos"
    }, 
    {
      "family": "Malliaros Stefanos"
    }, 
    {
      "family": "Xenakis Christos"
    }
  ], 
  "type": "article", 
  "id": "2633020"
}
137
84
views
downloads
All versions This version
Views 137137
Downloads 8484
Data volume 60.5 MB60.5 MB
Unique views 119119
Unique downloads 7474

Share

Cite as