Weak password hashing

Weak password hashing in C#

Description

Storing passwords with a fast hash such as SHA-256, or configuring a password hasher with too few iterations, lets an attacker make rapid offline guesses against stolen hashes.

Potential impact

  • A database leak can lead to password recovery, account takeover and privilege escalation.

Remediation

Use ASP.NET Core PasswordHasher, bcrypt, Argon2, scrypt, or PBKDF2 with sufficient work and per-password salts.

Examples

Before

csharp
return SHA256.HashData(Encoding.UTF8.GetBytes(password));

After

csharp
var hasher = new PasswordHasher<User>();
return hasher.HashPassword(user, password);

Explanation:

  • Before: Fast hashes and low password-hashing work factors let attackers test guesses efficiently offline.
  • After: Use ASP.NET Core PasswordHasher, bcrypt, Argon2, scrypt or PBKDF2 with a suitable work factor and a separate salt for each password.

References