Ask a Question
Ask Question Login
Corporate Training
  1. Community
  2. Cyber Security
  3. Question
Cyber Security

Is it possible to securely store passwords using reversible encryption?

Asked by Andrea Bailey Mar 17, 2022 958 views 1 answer
Share

About this question

Everyone says that you need to use a non-reversible hash when you store passwords so that even if your database is leaked, the passwords themselves are still safe. I'm wondering if there is any way to use reversible encryption to store passwords.


At the very least, you would need to require that any exploit that leaks the database (SQL injection, server shell access, etc.) doesn't leak the encryption key and that it would not reasonably be possible to figure out the encryption key using a known plaintext password if you have the leaked database.


I'm not seriously considering doing this because it seems like even if it's technically possible it would be hard to do correctly, but it seems like an interesting problem.

Your answer

1 Answer

More Cyber Security discussions

Learn & Explore

Free tutorials and interview questions from industry experts — learn the skill, then get ready to prove it.

Latest Cyber Security Blogs

Guides, tips and career advice on Cyber Security from JanBask experts.