Name
B2. Better Living Through Better Passwords
Track
Architecture & Operations
Date
Tuesday, June 8, 2021
Time
11:15 AM - 12:15 PM
Description

There's been a seismic shift in password guidance. NIST says no complexity, no forced change. PCI DSS 4.0 is not yet published but it’s anticipated that authentication requirements are evolving. The hardware and software improvements in hashing arising from crypto-currency mining put increased pressure on storing a password securely. Memory-hard hashing methods are one defense to off-line hash attacks. And then there are those who advocate getting rid of passwords. The speakers will provide guidance on: syntax, management, and strengthening secure storage of passwords; where DSS 4.0 might be going; and purported password replacements. They will describe how memory-hard hashing works.

Learner Objectives

After attending this session, learner will: 

  • Understand the new NIST guidance for passwords and be able to update their authentication policies to improve security while easing the burden on their users. 
  • Learn how memory-hard hashing works to strongly secure stored passwords.
  • Learn the possible directions of PCI DSS 4.0
  • Become aware of proposed “passwordless” authentication methods.