Custom Development

User Account Security Using Password-Based KDF’s

Max McCarty

There are different ways to implement security in a system based on many different factors.  When implementing security for your user accounts, we give lots of thought to security in relation to a non-compromised system, where attackers are still trying to penetrate and gain access to account data.

 How about security playing a role to systems that have been compromised?  Where the attacker has gained access to resources such as the database and source code?  What can the security we put in place now, help with then?

We’re going to take a close look at user account security through dissecting the building blocks, shortcomings and pitfalls of password hashing.

http://lockmedown.com/user-account-security-with-pbkdfs

 

Max McCarty
ABOUT THE AUTHOR

Max McCarty is a Senior Technical Consultant at Summa with a passion for breathing life into big ideas. He is the founder and owner of LockMeDown.com and host of the popular Lock Me Down podcast. As a software engineer, Max’s focus is on software security, and strongly believes in empowering the everyday developer with the information to write more secure software. When he’s not building new applications or writing about web security, you’ll find Max burning calories with his kids and spending time with his wonderful family. He’s also a serious history buff.