In short: there's plenty of reasons to be against this law without constructing new outrages.
In short: there's plenty of reasons to be against this law without constructing new outrages.
It does outlaw hashed passwords in practice.
EDIT: as others have pointed out, you could simply store the plaintext passwords in another file with greater security, and have hashed ones in the DB. An even better option would be simply to get the hell out of france.
Or, start a consulting business in france to help people comply with this, and rake it in.
... WHERE user.password = hash(input)
to ... WHERE user.password = hash(input) OR user.password = input
Or was your point that this would eliminate the benefits of using an adaptive hash like bcrypt to slow down brute forcing?Also if you wanted to make it secure you could restrict hash passwords to work only from certain IP addresses so you either have to be using a company internal machine or say the IP addresses from a police station.
He was referring to my rebuttal, which was initially downvoted for some reason.
... WHERE user.hashed_password = hash(input) OR user.hashed_password = input
So the user can provide their password which gets hashed and compared to the stored hash, OR the hash can be given to law enforcement if required and can be used in place of the real password.This solves the problem of passwords being stored in plaintext (indeed a problem with frequent password reuse) while apparently getting around this silly French law.
Sure if the database is compromised anyone will be able to login to anyone's account, but the database is compromised so who cares?
WHERE user.password = hash(input) OR hash(user.password + skeleton_key) = input
If the police want to log into a user's account without their password, they combine the hash of their password with the skeleton key, hash that, and submit it as the password.Of course, now you have to keep skeleton_key a secret. Presumably you wouldn't store it in the same database as the password hashes, so losing the database wouldn't immediately grant access to everyone's account.
I'm not claiming this is particularly secure. In fact, it's kind of the opposite: it's intentionally adding a back door to your authentication system. But at least it's a door rather than a gaping hole :)
It's totally legal to store the hashed value with your live database as normal to provide authentication, and store the plain text version in a write only file on a separate system to try and give some additional level of security. This isn't a great solution, but it does provide hashed passwords for regular work, and plain text for when the police ask for it.
It's obviously a pretty stupid law, but to say it "outlaws" hashed passwords is just nonsense.
You are splitting hairs. It outlaws passwords where only the (salted) hash and not the plaintext is stored, which is the whole point of what's commonly known as "hashed passwords".
store the hashed value with your live database ... and store the plain text version in ... a separate system
Call that seperate system "the moneypot". I'm tempted to suggest that people just try that and see how that works out for them, given the inevitablity of failures of security and vigilance. But for the sake of the rest of us, let's not.
If someone has that level of control over your system to access a write only file on a separate secured system, make a copy and extract it somewhere else, they probably also have enough access to insert a piece of code into your authentication system to dump all the plaintext passwords to a separate file as people login over time.
The message remains the same for all users regardless of this law - Don't reuse passwords, you can't trust their security.
of course you aren't. We know this because you say you aren't. What you are is making a nuanced distinction between what you mean when you say "stores hashed passwords" and what is commonly meant by that.
The password (as well as full name, postal address, pseudonym, phone number) only needs to be kept if it is collected. So you must keep the password (and be able to give it upon request) only in the case you already store it.
XKCD really is the geek equivalent of quoting scripture. Lessons for living.
Writing laws and contracts, in a way, seems like trying to make secure software. One has to define everything, and evaluate all possible "attack angles".