1
1

00:00:01,130  -->  00:00:02,840
<v Instructor>Hi, and welcome back.</v>
2

2

00:00:02,840  -->  00:00:03,673
In this video we're going to talk
3

3

00:00:03,673  -->  00:00:05,563
about encrypting passwords.
4

4

00:00:06,810  -->  00:00:11,053
If we go and register a user, such as rolf@example.com,
5

5

00:00:12,340  -->  00:00:15,163
then that gets saved into the database.
6

6

00:00:16,397  -->  00:00:17,903
Then we can go into MongoDB,
7

7

00:00:19,178  -->  00:00:20,794
make sure you're using the right database,
8

8

00:00:20,794  -->  00:00:23,940
type db.users.find, and you'll see
9

9

00:00:23,940  -->  00:00:27,960
that a user is created, but the password
10

10

00:00:27,960  -->  00:00:31,780
is 1234, which is what I typed in the field.
11

11

00:00:31,780  -->  00:00:34,250
This is a big security risk.
12

12

00:00:34,250  -->  00:00:37,930
Whenever you have data about users
13

13

00:00:37,930  -->  00:00:41,980
that is personally identifiable or sensitive,
14

14

00:00:41,980  -->  00:00:45,538
it should be encrypted, so that if you're database
15

15

00:00:45,538  -->  00:00:48,050
gets compromised, nobody can access the data
16

16

00:00:48,050  -->  00:00:50,954
and use it for malicious purposes,
17

17

00:00:50,954  -->  00:00:52,553
or really for any other purposes.
18

18

00:00:52,553  -->  00:00:53,973
It should just be encrypted so nobody can access it.
19

19

00:00:56,576  -->  00:00:59,470
The only way to use encrypted data
20

20

00:00:59,470  -->  00:01:03,412
is by comparing the encrypted data,
21

21

00:01:03,412  -->  00:01:05,960
which is a bunch of gibberish, essentially,
22

22

00:01:05,960  -->  00:01:09,373
to the same thing, also encrypted.
23

23

00:01:10,676  -->  00:01:12,099
So here's what we're gonna do,
24

24

00:01:12,099  -->  00:01:13,300
we're gonna turn this into a very long
25

25

00:01:13,300  -->  00:01:15,743
string of encrypted password.
26

26

00:01:17,020  -->  00:01:19,090
Now, when the user logs in,
27

27

00:01:19,090  -->  00:01:21,260
or when they give us the password later on,
28

28

00:01:21,260  -->  00:01:23,680
what we'll do, is we will take the password,
29

29

00:01:23,680  -->  00:01:25,570
we will also encrypt it.
30

30

00:01:25,570  -->  00:01:28,660
And then when we will compare the two encrypted versions.
31

31

00:01:28,660  -->  00:01:32,853
So we are never going to be decrypting this data.
32

32

00:01:33,760  -->  00:01:36,663
Indeed, decrypting something is very difficult.
33

33

00:01:37,608  -->  00:01:40,358
So it's not like it can be done all that easily either.
34

34

00:01:41,689  -->  00:01:42,720
What that's gonna do is, if somebody
35

35

00:01:42,720  -->  00:01:44,710
hacks into a database or something like
36

36

00:01:44,710  -->  00:01:47,360
that, they're not gonna be able to read what's in it.
37

37

00:01:48,230  -->  00:01:50,090
Let's go and do that.
38

38

00:01:50,090  -->  00:01:52,920
In order to encrypt passwords using Python,
39

39

00:01:52,920  -->  00:01:55,180
I like using a library called passlib.
40

40

00:01:57,072  -->  00:01:58,889
So go over to your project interpreter,
41

41

00:01:58,889  -->  00:02:00,290
make sure the right interpreter is selected for
42

42

00:02:00,290  -->  00:02:03,330
this project, press the little plus icon
43

43

00:02:03,330  -->  00:02:04,330
and type in passlib.
44

44

00:02:06,010  -->  00:02:09,763
And make sure it is just passlib and not anything else.
45

45

00:02:11,267  -->  00:02:12,553
And let's go and instal that.
46

46

00:02:14,511  -->  00:02:17,751
When that's installed, we can close it and press okay.
47

47

00:02:17,751  -->  00:02:20,080
And then we're gonna go over to our utils package,
48

48

00:02:20,080  -->  00:02:23,469
and we're going to import something from that package.
49

49

00:02:23,469  -->  00:02:27,557
We're gonna say, from passlib.hash import pbkdf2 sha512.
50

50

00:02:29,010  -->  00:02:32,611
What this does is it uses the algorithm,
51

51

00:02:32,611  -->  00:02:36,220
pbkdf2 to do encryption.
52

52

00:02:36,220  -->  00:02:39,120
Pbkdf2 is one of the most secure algorithms to date.
53

53

00:02:39,120  -->  00:02:41,420
So it is recommended that you use that one,
54

54

00:02:41,420  -->  00:02:43,363
or a similarly secure algorithm.
55

55

00:02:44,349  -->  00:02:45,789
In this course, we'll be using this one.
56

56

00:02:45,789  -->  00:02:47,143
Passlib has a bunch of them,
57

57

00:02:47,143  -->  00:02:48,485
you can do your research and choose
58

58

00:02:48,485  -->  00:02:49,768
a different one, if you like.
59

59

00:02:49,768  -->  00:02:51,211
There's different reasons to choose
60

60

00:02:51,211  -->  00:02:52,911
different algorithms, such as the speed
61

61

00:02:52,911  -->  00:02:55,790
at which they can create an encrypted password,
62

62

00:02:55,790  -->  00:02:57,270
the speed at which they can check encrypted passwords
63

63

00:02:57,270  -->  00:02:58,960
as well as their security, i.e.,
64

64

00:02:58,960  -->  00:03:00,703
how easy it is to decrypt them.
65

65

00:03:03,331  -->  00:03:06,431
In here we're gonna add a couple more static methods.
66

66

00:03:06,431  -->  00:03:08,509
The first one is gonna be hash password.
67

67

00:03:08,509  -->  00:03:11,208
It's gonna take in a plain text password
68

68

00:03:11,208  -->  00:03:12,970
that the user sends us, and is going to return
69

69

00:03:12,970  -->  00:03:17,970
pbdk2 sha512.encrypt of the password.
70

70

00:03:19,170  -->  00:03:21,070
And that's just going to encrypt the password,
71

71

00:03:21,070  -->  00:03:23,324
turn it into a bunch of gibberish.
72

72

00:03:23,324  -->  00:03:24,328
I'll show you what it looks like
73

73

00:03:24,328  -->  00:03:26,033
in just a moment, and that's it.
74

74

00:03:26,950  -->  00:03:29,280
The other method we're gonna do
75

75

00:03:29,280  -->  00:03:32,910
is called check hashed password,
76

76

00:03:32,910  -->  00:03:34,933
hashed password, like that.
77

77

00:03:35,932  -->  00:03:39,780
It's gonna take in a password and also a hashed password,
78

78

00:03:39,780  -->  00:03:41,633
and it's going to return a Boolean,
79

79

00:03:42,586  -->  00:03:46,580
and this is gonna do return pbkdf2 sha512.verify
80

80

00:03:46,580  -->  00:03:48,903
of the password and the hashed password.
81

81

00:03:50,140  -->  00:03:52,660
Again, what this does is it essentially
82

82

00:03:52,660  -->  00:03:54,970
re-encrypts the password and then
83

83

00:03:54,970  -->  00:03:57,263
compares it to make sure that they match.
84

84

00:03:58,400  -->  00:04:00,360
Let's restart our application.
85

85

00:04:00,360  -->  00:04:02,480
Oh, actually, before we do that we need to go
86

86

00:04:02,480  -->  00:04:07,200
to our user model and make sure to use
87

87

00:04:08,290  -->  00:04:11,800
utils.hashpassword when saving
88

88

00:04:11,800  -->  00:04:14,238
the password into the database.
89

89

00:04:14,238  -->  00:04:16,101
So here we will create a user
90

90

00:04:16,101  -->  00:04:18,570
with the hashed password in there.
91

91

00:04:18,570  -->  00:04:22,363
All right, we can restart, go back to Chrome.
92

92

00:04:24,377  -->  00:04:27,490
We're going to now create bob@example.com
93

93

00:04:27,490  -->  00:04:28,890
and we're gonna sign him up.
94

94

00:04:30,558  -->  00:04:32,761
All fine; go back to the terminal,
95

95

00:04:32,761  -->  00:04:35,484
find the user, and now you can see
96

96

00:04:35,484  -->  00:04:39,293
the password is much longer, it is all of this string, here.
97

97

00:04:40,320  -->  00:04:42,460
Now, I said earlier, a couple of times,
98

98

00:04:42,460  -->  00:04:44,823
that this is a bunch of gibberish,
99

99

00:04:45,683  -->  00:04:46,950
and that's not really true.
100

100

00:04:46,950  -->  00:04:51,950
What we have here is a dollar sign,
101

101

00:04:52,121  -->  00:04:54,140
and then pbk2 sha512, this tells us
102

102

00:04:54,140  -->  00:04:59,140
that this is a pbk2 sha 512 encrypted password.
103

103

00:04:59,841  -->  00:05:00,674
Then it's got a number, the number
104

104

00:05:00,674  -->  00:05:02,533
of rounds used to encrypt the password.
105

105

00:05:03,423  -->  00:05:05,362
And then it's got a bunch of characters,
106

106

00:05:05,362  -->  00:05:06,833
and this is the encrypted password.
107

107

00:05:07,841  -->  00:05:09,880
What happens is, we have to use
108

108

00:05:09,880  -->  00:05:12,230
the same number of rounds, and the same algorithm
109

109

00:05:12,230  -->  00:05:15,463
when we check the password, so this is why
110

110

00:05:15,463  -->  00:05:17,380
this is stored alongside the encrypted password,
111

111

00:05:17,380  -->  00:05:19,950
so that when we go back to our utils
112

112

00:05:19,950  -->  00:05:22,880
and check the password, this method here,
113

113

00:05:22,880  -->  00:05:24,830
and look at the hashed password,
114

114

00:05:24,830  -->  00:05:27,240
make sure the algorithm is correct
115

115

00:05:28,083  -->  00:05:29,230
and then encrypt this password with
116

116

00:05:29,230  -->  00:05:30,910
the same number of rounds, so
117

117

00:05:31,821  -->  00:05:34,050
that the result will be the same.
118

118

00:05:34,050  -->  00:05:37,310
Then if we take 1234, it should match exactly,
119

119

00:05:37,310  -->  00:05:39,900
and we'll know that it is correct.
120

120

00:05:39,900  -->  00:05:42,219
Going the other way around though,
121

121

00:05:42,219  -->  00:05:45,790
taking a hashed password and turning it into 1234 is really
122

122

00:05:45,790  -->  00:05:49,140
difficult, even if you know the number of rounds used.
123

123

00:05:49,140  -->  00:05:51,990
That's because it's almost impossible
124

124

00:05:51,990  -->  00:05:55,300
to take something that has been hashed
125

125

00:05:55,300  -->  00:05:57,640
and calculating backwards, this is just
126

126

00:05:57,640  -->  00:05:59,313
not how these algorithms work.
127

127

00:06:00,951  -->  00:06:02,175
If you're more interested in security,
128

128

00:06:02,175  -->  00:06:03,008
and you wanna learn about these algorithms,
129

129

00:06:03,008  -->  00:06:05,860
by all means, find out more about them.
130

130

00:06:05,860  -->  00:06:09,000
I am not a security expert, so I cannot teach you
131

131

00:06:09,000  -->  00:06:13,300
more about algorithms and encryption, but yeah,
132

132

00:06:13,300  -->  00:06:16,093
this is how you encrypt passwords using Python,
133

133

00:06:17,252  -->  00:06:19,250
and do use a secure algorithm.
134

134

00:06:19,250  -->  00:06:20,940
All right, thanks for joining me in this video.
135

135

00:06:20,940  -->  00:06:24,760
We are now storing encrypted passwords in the database.
136

136

00:06:24,760  -->  00:06:27,600
When we login, we will have to make sure to use
137

137

00:06:27,600  -->  00:06:29,580
this check hashed password, as otherwise
138

138

00:06:29,580  -->  00:06:30,690
we won't be able to determine
139

139

00:06:30,690  -->  00:06:32,910
whether the password is correct or not,
140

140

00:06:32,910  -->  00:06:35,610
but we are now ready to actually do
141

141

00:06:35,610  -->  00:06:37,430
allow users to login.
142

142

00:06:37,430  -->  00:06:39,220
Let's look at that in the next video.
143

143

00:06:39,220  -->  00:06:40,170
I'll see you there.
