Skip to main content

Unit 4 · Topic 4.2

4.2 Authentication

Logging in is how a device decides who you are, and adversaries attack every part of that process. This topic covers why systems store password hashes with salt, how online and offline password attacks work, the four authentication factors and MFA, and the login settings that make guessing harder.

Key terms

  • cryptographic hash
  • salt
  • password spraying
  • credential stuffing
  • rainbow table
  • authentication factors

Cryptographic hashes

A cryptographic hash function takes data of any length and produces a fixed-length string of bits called the hash (also called a checksum, message digest or digest). Well-known ones include MD5 (128 bits), SHA-1 (160 bits), SHA-256 (256 bits), SHA-512 (512 bits), NTHash and RIPEMD-160.

Good hash functions have four properties. They're repeatable (the same input always gives the same hash), fixed-length (the output size never changes, whether you hash one letter or a whole movie), pre-image resistant (given a hash, you can't work out the input) and collision resistant (it's very hard to find two inputs with the same hash).

An n-bit hash has 2ⁿ possible outputs, but there are infinitely many possible inputs, so collisions must exist. They just need to be impractical to find. When someone finds an efficient way to force collisions, the function is deprecated, meaning it's no longer used where security matters. MD5 and SHA-1 are deprecated.

Storing passwords safely

A system shouldn't store your actual password. If an adversary stole a plaintext password file, they'd instantly know everyone's password. Instead, the system stores the hash. When you log in, it hashes what you typed and compares that to the stored hash. A match means you're in.

But if two users pick the same password, they'd have identical hashes, and cracking one cracks both. So systems add salt: a few random bits, unique to each user, hashed together with the password. Same password plus different salt gives a different hash.

Online password attacks

If an adversary gets a real user's password and there's no MFA, they can do anything that user can do. Online attacks try username and password pairs on a live login portal:

  • Trying stolen or leaked credentials. Stolen user databases are sold or posted online, and many people reuse passwords, so a password leaked from one site often opens others.
  • Password spraying: trying one common password against many different accounts.
  • Credential stuffing (as this course defines it): trying common default credentials, like the factory admin login on a router, switch or IoT device, or stolen account credentials. Outside this course, the term usually means replaying username and password pairs leaked from other sites.

Offline password attacks

Offline attacks happen after an adversary steals a password hash database. On their own computer, they hash huge numbers of guesses and compare each result to the stolen hashes. Because nothing touches the real login page, account lockouts can't stop them, and nothing shows up in the victim's logs.

Brute force tests every possible password; a dictionary attack tests a list of common passwords; a rainbow table attack uses a precomputed table of common passwords and their hashes, sorted by hash, so each stolen hash can be looked up quickly. Salt defeats rainbow tables, since a precomputed table can't include every user's random salt.

Authentication factors and MFA

  • Something you know (knowledge): password, PIN, answers to challenge questions. It must be hard to guess, but that can also make it hard to remember.
  • Something you have (possession): access card, bank card, phone, authentication token. The harder it is to steal or copy, the better.
  • Something you are (biometric): fingerprint, palm print, face, iris or retina, voice. Hard to duplicate because it's unique to you.
  • Somewhere you are (location): Wi-Fi, GPS, time zone settings or IP address. Rules can allow or deny access based on location.
  • Multifactor authentication (MFA) requires at least two separate factors, which is more secure than one. A password plus a security question is still just one factor type (two things you know), so it isn't true MFA.

Login settings you can configure

  • Complexity: new passwords must include each character set (uppercase, lowercase, digits, special characters).
  • Minimum length: longer passwords take far longer to crack. Current U.S. guidance (NIST SP 800-63B, revision 4, August 2025) puts length ahead of complexity: at least 15 characters when a password is the only factor, and no forced mix of character types.
  • Maximum age: users must change passwords every set number of days, often 90 or 120. Changing a stolen password can lock an adversary out, but NIST's current guidance (SP 800-63B, revision 4, August 2025) says not to force changes on a schedule, only when there's evidence a password was compromised, because people respond with predictable patterns like Spring2027! becoming Summer2027!. On the exam, know both the setting and this trade-off.
  • Password history: the system stores several previous password hashes, often 5 to 10, so users can't reuse them.
  • Lockout: after a set number of failed attempts, often 3 to 5, the account locks for a period, which stops endless online guessing.

Worked examples

Try each one yourself first, then open the solution.

  1. Example 1

    What salt changes

    Ana and Ben both use the password sunflower. In an unsalted system, the stored SHA-256 hash for both is 8f398886c326b5f8f07b20ac250c87de6723e062474465273fe1524f2b9092fa. Explain the two weaknesses this creates and how salt fixes them.

    Show the solution
    1. Step 1: Hashes are repeatable, so the same password always gives the same hash. An adversary who steals the database can see that Ana and Ben share a password. Cracking one cracks both.
    2. Step 2: Because the hash isn't salted, the adversary can look it up in a rainbow table of common passwords. sunflower is a common word, so the hash is likely already in the table.
    3. Step 3: With salt, each user gets different random bits mixed in before hashing, so Ana's and Ben's stored hashes differ, and a precomputed table without their salts won't match either one.

    Answer: Unsalted, identical passwords produce identical hashes (crack one, crack both), and the hash can be found in a precomputed rainbow table. Unique salt makes each user's hash different, which hides shared passwords and makes rainbow tables useless.

  2. Example 2

    Is it MFA?

    For each login, list the factor types and say whether it's MFA: (a) password, then a code from an authenticator app on your phone; (b) password, then the name of your first school; (c) fingerprint, then the system checks you're on the office Wi-Fi.

    Show the solution
    1. Step 1: (a) Password is knowledge; the app code proves you have the phone (possession). Two different factors, so it's MFA.
    2. Step 2: (b) Password and a challenge question are both knowledge. One factor type, so it isn't MFA.
    3. Step 3: (c) Fingerprint is biometric; the Wi-Fi check is location. Two different factors, so it's MFA.

    Answer: (a) Knowledge + possession: MFA. (b) Knowledge + knowledge: not MFA. (c) Biometric + location: MFA.

  3. Example 3

    Length versus complexity

    Compare how many possible passwords an offline brute-force attack must search for: (a) 8 characters, lowercase letters only; (b) 8 characters from all 95 printable keyboard characters; (c) 16 characters, lowercase letters only.

    Show the solution
    1. Step 1: Each position has a fixed number of choices, so the total is choices raised to the length.
    2. Step 2: (a) 26⁸ = 208,827,064,576, about 2.09 × 10¹¹.
    3. Step 3: (b) 95⁸ = 6,634,204,312,890,625, about 6.63 × 10¹⁵, roughly 32,000 times more than (a).
    4. Step 4: (c) 26¹⁶ ≈ 4.36 × 10²², about 6.6 million times more than (b), even with only lowercase letters.
    5. Step 5: Conclusion: complexity helps, but length grows the search space much faster.

    Answer: (a) about 2.09 × 10¹¹; (b) about 6.63 × 10¹⁵; (c) about 4.36 × 10²². The 16-character lowercase password has by far the largest search space.

Common mistakes

  • Saying hashing is encryption that can be reversed. Hashes are one-way; offline attacks work by hashing guesses and comparing, not by undoing the hash.
  • Thinking account lockout stops offline attacks. Offline attacks never touch the login page, so lockouts don't apply.
  • Mixing up password spraying and credential stuffing. Spraying tries one common password on many accounts; stuffing tries default or stolen username and password pairs.
  • Calling two knowledge items MFA. MFA needs two different factor types.

On the exam

  • Expect questions on why systems store salted hashes, which attack is described (online or offline, spraying or stuffing, brute force, dictionary or rainbow table) and which factor a method uses.
  • If asked to configure login settings, give specific values and explain what each stops, for example a lockout after 5 failed attempts to stop online guessing.

Connected topics

Videos

  • AP Cybersecurity Topic 4.2.a - Authentication Explanations and MCQs!

    Dr_WuWatch on YouTube (opens in a new tab)

  • How NOT to Store Passwords! - Computerphile

    ComputerphileWatch on YouTube (opens in a new tab)

  • Multifactor Authentication - CompTIA Security+ SY0-701 - 4.6

    Professor MesserWatch on YouTube (opens in a new tab)

  • Passwords & hash functions (Simply Explained)

    Simply ExplainedWatch on YouTube (opens in a new tab)

  • How Hackers Steal Passwords: 5 Attack Methods Explained

    IBM TechnologyWatch on YouTube (opens in a new tab)

  • AP Cybersecurity Topic 4.2.d - Login settings - Explanations and MCQs!

    Dr_WuWatch on YouTube (opens in a new tab)

Check yourself: 4.2 Authentication

4 questions on 4.2 Authentication. Pick an answer to see if you got it, and why.

InputSHA-256 output
The sentence "Bring snacks for Friday's meeting."fd3988b4649608503b32a42907a24492fd3058d430c2e5c351a16afc51858cf9
The same sentence with ! instead of .4dff882e387f2bf76c1bda9482b4a3c2fc7cf287735356b3510f6d0bbecf3019
A 5,000-character documentc59d3c0480cc2d71d8f646e735e92da65450311eec46e81a5db8c7e6e8a92054

SHA-256 outputs computed for this question

Question 1 of 4

Which property of cryptographic hash functions do all three rows show?

Question 2 of 4

The first two inputs differ by one character. What does a comparison of their outputs show?

Question 3 of 4

Why should a website store hashes of its users' passwords instead of the passwords themselves?

Question 4 of 4

A user types a password into a login page. The system stores only password hashes. What does the system do to decide whether the password is correct?

0 of 4 answered