Protecting Passwords with Oblivious Cryptography with Adam Everspaugh

Summary Current schemes to protect user passwords like bcrypt, scrypt, and iterative hashing are insufficient to resist attacks when password digests are stolen. We present a modern cloud service, called Pythia, which protects passwords using a cryptographically keyed pseudorandom function (PRF). Unlike existing schemes like HMAC, Pythia permits key updates as a response to compromises. Key updates nullify stolen password digests, enable digests to be updated to the new key, and don't require users to change their passwords. The keystone of Pythia is a new cryptographic construction called a partially oblivious PRF that provides these new features.

S1.E8 ∙ Protecting Passwords with Oblivious Cryptography with Adam Everspaugh

Directed : Unknown

Written : Unknown

Stars : Michael Goetzman Demetrius Comes Ed Abrams Richard Thieme

0

Details

Genres : Documentary

Release date : Jul 23, 2022

Countries of origin : United States

Official sites : Official website

Language : English

Production companies : 249 Studios

Summary Current schemes to protect user passwords like bcrypt, scrypt, and iterative hashing are insufficient to resist attacks when password digests are stolen. We present a modern cloud service, called Pythia, which protects passwords using a cryptographically keyed pseudorandom function (PRF). Unlike existing schemes like HMAC, Pythia permits key updates as a response to compromises. Key updates nullify stolen password digests, enable digests to be updated to the new key, and don't require users to change their passwords. The keystone of Pythia is a new cryptographic construction called a partially oblivious PRF that provides these new features.

Details

Genres : Documentary

Release date : Jul 23, 2022

Countries of origin : United States

Official sites : Official website

Language : English

Production companies : 249 Studios

Edit Focus

All Filters