
Sign up to save your podcasts
Or
Michal Špaček shares the story of how the Password Storage project has convinced hundreds of companies to publicly disclose their password storage practices and assigned each a grade based on how well they follow best practices.
We discuss hashing algorithms and the technology behind storing passwords securely. Learn why a company who follows the technical best practices might still not earn an A grade if they do not have a public disclosure, or if they rely on an Invisible Disclosure.
We compare the Password Storage project to other fantastic security tools, including SSL Labs and Mozilla Observatory.
Michal outlines how the grading criteria will change in the short term, highlights the desire to get more companies included in the data set, and contemplates how the project will continue to grow over time.
This episode was initially published in August 2019, the 5 year anniversary of Michal’s talk at BSides Las Vegas 2014, which planted the seeds that eventually grew into the Password Storage project. Happy birthday, Password Storage!
Social media & website
Resources mentioned in episode
You can find the host of The All Things Auth Podcast on Twitter @conorgil.
Canonical URL: https://allthingsauth.com/podcast/005-michal-spacek-of-password-storage
5
99 ratings
Michal Špaček shares the story of how the Password Storage project has convinced hundreds of companies to publicly disclose their password storage practices and assigned each a grade based on how well they follow best practices.
We discuss hashing algorithms and the technology behind storing passwords securely. Learn why a company who follows the technical best practices might still not earn an A grade if they do not have a public disclosure, or if they rely on an Invisible Disclosure.
We compare the Password Storage project to other fantastic security tools, including SSL Labs and Mozilla Observatory.
Michal outlines how the grading criteria will change in the short term, highlights the desire to get more companies included in the data set, and contemplates how the project will continue to grow over time.
This episode was initially published in August 2019, the 5 year anniversary of Michal’s talk at BSides Las Vegas 2014, which planted the seeds that eventually grew into the Password Storage project. Happy birthday, Password Storage!
Social media & website
Resources mentioned in episode
You can find the host of The All Things Auth Podcast on Twitter @conorgil.
Canonical URL: https://allthingsauth.com/podcast/005-michal-spacek-of-password-storage