Authentication and Password Security

Ibrahim Habib
Sama Essam
Julia George

2026-10-01

1 Authentication & The Password Problem

1.1 Authentication vs. Authorization

Concept Question Example
Authentication Who are you? Logging in with a password
Authorization What can you do? Admin vs. regular user permissions

Note

These are often confused. Authentication proves identity. Authorization grants access. They are not the same thing.

1.2 Real-World Analogy

Authentication: Showing your ID at the door.

Authorization: Being allowed into the VIP section.

You can be authenticated (ID is valid) but not authorized (not on the VIP list).

1.3 The Password Problem

Users are terrible at passwords:

  • Reuse: Same password across multiple sites
  • Weak choices: 123456, password, pet names, birthdays
  • Write them down: Sticky notes, plain text files
  • Sharing: “Hey, what’s the Netflix password?”

The most common password in 2023 was still 123456.

1.4 How Passwords Get Compromised

Attack How it works
Phishing Trick the user into entering their password on a fake site
Brute force Try every possible combination
Credential stuffing Use leaked passwords from other breaches
Shoulder surfing Physically watch someone type
Data breaches Steal the password database directly

1.5 The Math of Brute Force

\[\text{Keyspace} = (\text{character set size})^{\text{password length}}\]

Password type Keyspace Time to brute force 1
8 lowercase letters \(26^8 \approx 200\) billion Minutes
8 mixed + symbols \(95^8 \approx 6.6\) quadrillion Days
12 mixed + symbols \(95^{12} \approx 5.4 \times 10^{23}\) Millions of years

Takeaway: Length wins. Every character you add multiplies the keyspace.

2 Security in Transit

2.1 The Oldest Problem in Security

People have wanted to send secret messages for thousands of years.

Caesar Cipher (~50 BC): Shift each letter by a fixed number.

Enigma Machine (1920s–1940s): Electromechanical rotor cipher used by Nazi Germany. Far more complex, but built on the same idea.

Enigma Machine

2.2 The Flaw of Symmetric Encryption

Every cipher from Caesar to Enigma shares the same problem:

Both sides need the same key.

  • Enigma operators received key books (i.e., physical documents listing daily settings)
  • If a key book was captured, all messages could be decrypted
  • The key had to be exchanged securely before any secure communication could begin

This is the key distribution problem.

2.3 The Dark Alley Problem

For symmetric encryption to work, you had to meet your friend in a dark alley and agree on the secret key without anyone watching.

This worked for militaries. They had couriers, diplomatic pouches, locked briefcases.

But then the internet happened.

2.4 You’ve Never Met Bezos in a Shady Place

You send your credit card number to Amazon every day.

You never met Jeff Bezos in a parking garage to exchange a secret key.

So how does that work?

This is the question that Diffie, Hellman, and RSA set out to answer.

2.5 The Breakthrough: Public & Private Keys

Diffie-Hellman (1976) and RSA (1977) solved the key distribution problem.

The idea:

  • A public key that anyone can use to lock (encrypt)
  • A private key that only you can use to unlock (decrypt)
  • Knowing the public key doesn’t help you figure out the private key

You publish your public key to the world. Anyone can send you a secret message. Only you can read it.

Fun fact

GCHQ (the UK’s intelligence agency) discovered the same idea in 1973 (four years earlier). But it was classified, so Diffie, Hellman, and RSA got the credit.

2.6 Why It Works: One-Way Functions

A one-way function is easy to compute forward, but practically impossible to reverse.

  • Forward: 7,919 × 7,907 = ? → Easy (it’s 62,615,533)
  • Reverse: 62,615,533 = ? × ? → Hard

RSA relies on this. Your public key is derived from two huge primes multiplied together (hundreds of digits). Recovering those primes from the product is computationally infeasible.

2.7 P vs NP

Why “computationally infeasible” and not “truly impossible”?

Because no one has proven that one-way functions can’t be reversed efficiently.

This is the P vs NP problem: one of the seven Millennium Prize Problems (worth $1,000,000).

Most computer scientists believe P ≠ NP. But nobody has proven it.

3 Security at Rest

3.1 Storing Passwords

Your password arrived safely.

Now the server needs to store it. But not with encryption. If someone steals the database and the key, they can decrypt everything.

We need something one-way: a function that verifies “is this the right password?” without ever being able to recover the original.

That’s hashing.

3.3 Why Hashing Alone Isn’t Enough

If you hash passwords without a salt:

  • Two users with password cat123 = same hash
  • An attacker can pre-compute hashes for millions of common passwords

This is a rainbow table: a massive lookup table of password-hash mappings.

Hashing without salt is barely better than plaintext.

3.4 Salt

A salt is a random value generated per user, prepended to the password before hashing.

Same password, different salt = different hash.

Rainbow tables become useless; the attacker would need a separate table for every possible salt.

3.5 What We Use Today: bcrypt

bcrypt is designed to be slow on purpose.

  • Regular hash functions (SHA-256) are designed to be fast which is bad for passwords, because attackers can try billions of guesses per second
  • bcrypt has a configurable work factor (i.e., you can make it slower as hardware gets faster)
  • It generates and stores the salt automatically

3.6 bcrypt in Practice

import bcrypt

password = b"After all this time? Always."

# Hash (salt is generated automatically)
hashed = bcrypt.hashpw(password, bcrypt.gensalt(rounds=12))

# Verify
bcrypt.checkpw(password, hashed)  # True

4 Beyond Passwords

4.1 Quick Question

If a system requires both a password AND a security question to log in, is that Multi-Factor Authentication?

No.

Both are “something you know.” That’s two methods, one factor.

MFA requires methods from different factor

4.2 The Three Factors

Factor What it means
Something you know Information you’ve memorized
Something you have A physical object you possess
Something you are A biometric trait unique to you

Multi-Factor Authentication = combining two or more of these different factors.

4.3 Something You Know

  1. Password
  2. PIN
  3. Security question answer
  4. Pattern lock
  5. Passphrase

4.4 Something You Have

  1. Hardware security key
  2. Smartphone with authenticator app (TOTP)
  3. Smart card / badge
  4. Phone number receiving SMS
  5. Email account (magic link)

4.5 Something You Are

  1. Fingerprint
  2. Facial recognition
  3. Iris scan
  4. Voice recognition

4.6 Why Factors > Methods

Two methods, same factor (NOT MFA):

  • Password + security question = Both “something you know”
  • A phishing attack can steal both in one go

Two different factors (MFA):

  • Password + authenticator app = “Know” + “Have”
  • Even if the password is phished, the attacker still doesn’t have your phone

The categories matter more than the count.

5 Recap

5.1 Key Takeaways

  1. Passwords are fragile: length beats complexity, but they’re still the weakest link
  2. Security in transit: public-key encryption lets you send secrets without needing to share a key in person
  3. Security at rest: hash passwords with bcrypt + salt, never store them reversibly
  4. Beyond passwords: MFA requires different factor, not just multiple methods

Any questions?

5.2 Q1: What is authentication?

  • Determining what resources a user can access
  • Verifying the identity of a user
  • Encrypting data before sending it
  • Logging user activity on a system

5.3 Q2: A user logs in successfully but cannot access the admin panel. What is missing?

  • Authentication
  • Authorization
  • Identification
  • Encryption

5.4 Q3: Which of the following makes a password strongest?

  • Adding a special character to a short password
  • Using a mix of uppercase and lowercase in 6 characters
  • Increasing the password length
  • Changing the password every 30 days

5.5 Q4: Which attack involves tricking a user into entering their password on a fake website?

  • Brute force
  • Phishing
  • Shoulder surfing
  • Credential stuffing

5.6 Q5: What is credential stuffing?

  • Guessing passwords by trying every combination
  • Watching someone type their password
  • Using leaked passwords from one site to log into another
  • Injecting malicious code into a login form

5.7 Q6: What is the fundamental challenge of symmetric encryption?

  • It is too slow for modern communication
  • It can only encrypt numbers
  • Both sides need to securely share the same key
  • It cannot be decrypted once encrypted

5.8 Q7: What problem did public-key cryptography solve?

  • Making encryption faster
  • Exchanging secrets without a pre-shared key
  • Preventing brute force attacks
  • Storing passwords securely

5.9 Q8: In public-key cryptography, which key do you share with everyone?

  • The private key
  • The public key
  • Both keys
  • Neither key, both are secret

5.10 Q9: What is a one-way function?

  • A function that can only be called once
  • A function that encrypts but cannot decrypt
  • A function that is easy to compute forward but practically impossible to reverse
  • A function that only works in one programming language

5.11 Q10: If P = NP were proven true, what would happen?

  • Computers would become faster
  • Passwords would become unnecessary
  • Modern cryptography would break
  • Nothing. It has no practical impact

5.12 Q11: Why should passwords be hashed instead of encrypted for storage?

  • Hashing allows the system to email users their forgotten passwords
  • Encryption is too slow for modern login systems
  • Hashes cannot be reversed to reveal original passwords if the database is stolen
  • Databases do not support storing encrypted data

5.13 Q12: What is a rainbow table?

  • A database of encrypted passwords
  • A tool for generating strong passwords
  • A pre-computed lookup table mapping passwords to their hashes
  • A list of the most common passwords

5.14 Q13: What does a salt do?

  • Encrypts the password before hashing
  • Slows down the hashing process
  • Ensures the same password produces different hashes for different users
  • Replaces the password with a random value

5.15 Q14: Why is bcrypt designed to be slow on purpose?

  • To reduce server energy consumption
  • To prevent users from logging in too quickly
  • To make brute force attacks computationally expensive
  • Because modern algorithms cannot run fast

5.16 Q15: What is the purpose of bcrypt’s configurable work factor?

  • It lets users choose the length of their password
  • It automatically rotates user passwords periodically
  • It allows hashing to be made slower as hardware gets faster
  • It encrypts database backups automatically

5.17 Q16: A system requires a password and a security question. Is this MFA?

  • Yes, it uses two authentication steps
  • Yes, it uses two different methods
  • No, both are “something you know”
  • No, security questions are not a valid authentication method

5.18 Q17: Which of the following is an example of “something you have”?

  • A PIN
  • A fingerprint
  • A hardware security key
  • A passphrase

5.19 Q18: Which of the following is an example of “something you are”?

  • Password
  • Smart card
  • TOTP code
  • Fingerprint

5.20 Q19: Which combination is a valid example of MFA?

  • Password + PIN
  • Security question + passphrase
  • Password + authenticator app
  • Pattern lock + password

5.21 Q20: Why is Multi-Factor Authentication effective against password phishing?

  • Phishing websites cannot capture passwords
  • It alerts the user before they visit a fake website
  • The attacker still lacks the second factor needed to log in
  • It automatically creates a new password for every login