1
00:00:05,120 --> 00:00:07,680
Alright, so we're going to finish
off our discussion of hash functions

2
00:00:07,680 --> 00:00:12,640
with a quick look at another use for them.
They're used a lot in security. In case you

3
00:00:12,640 --> 00:00:18,724
don't already know this, you should never,
never, never store passwords as plain text.

4
00:00:19,920 --> 00:00:24,080
There have been many cases where a
company's password database has been stolen,

5
00:00:24,080 --> 00:00:29,200
providing the criminals with large numbers of
email addresses, and the corresponding passwords.

6
00:00:29,200 --> 00:00:34,000
The very least that should be done, is to store
a hash of the password. When the user supplies

7
00:00:34,000 --> 00:00:40,160
their logon credentials, the hash of the password
they type is compared to the hash in the database.

8
00:00:40,160 --> 00:00:43,840
Importantly here, the original
password is never stored.

9
00:00:45,840 --> 00:00:49,600
If a website is able to tell you what
your password is, when you forget it,

10
00:00:49,600 --> 00:00:53,760
then they're storing your password as plain
text. In that case, it's only a matter of time

11
00:00:53,760 --> 00:00:58,720
before someone steals your password. Be very
careful on websites like that. Don't use the

12
00:00:58,720 --> 00:01:05,725
same password anywhere else, and definitely don't
let the site store your payment card details.

13
00:01:07,280 --> 00:01:11,360
Hash functions are one-way.
We saw that lemon and banana

14
00:01:11,360 --> 00:01:16,560
hashed to the same value, when we wrote our simple
hash function. If different keys can produce the

15
00:01:16,560 --> 00:01:21,188
same hash, then it should be obvious that
you can't get the key back from its hash.

16
00:01:21,188 --> 00:01:26,320
Our simple_hash function was very
simple, but the same applies to real hash functions.

17
00:01:26,320 --> 00:01:31,294
You can't reverse the process to
find out a value from its hash.

18
00:01:32,720 --> 00:01:36,720
Although you can't reverse a hash - there's no
way to retrieve a key from the hash itself -

19
00:01:36,720 --> 00:01:41,858
that doesn't mean hashes are totally secure.
Attackers can use a brute force approach.

20
00:01:41,858 --> 00:01:46,880
That involves generating millions of keys and
hashing them. When a hash matches a hash in a

21
00:01:46,880 --> 00:01:52,000
stolen database, they've found out what the
password was. Probably. They might not know

22
00:01:52,000 --> 00:01:58,014
the exact password if there's a collision, but
a good hash function should minimise collisions.

23
00:01:59,360 --> 00:02:03,920
A brute force attack can take a long time. But if
the criminals set their computer away, trying to

24
00:02:03,920 --> 00:02:08,160
crack a database with millions of entries, for a
week or more, but only cracks 10 percent of them after a

25
00:02:08,160 --> 00:02:15,276
week, that's still a lot of passwords. Even worse,
they then share their cracked databases online.

26
00:02:16,640 --> 00:02:20,560
The obvious thing to do, in a video
about hashing functions and security,

27
00:02:20,560 --> 00:02:24,160
would be to show you how to hash
passwords. But I'm not going to do that.

28
00:02:24,160 --> 00:02:29,297
I don't want to encourage you to store
passwords in any form - even hashed.

29
00:02:30,400 --> 00:02:34,960
If you really want to do that, then you'll want
to research computer security thoroughly

30
00:02:34,960 --> 00:02:38,960
So it's quite easy to produce something
that works. It's much, much harder

31
00:02:38,960 --> 00:02:42,640
to produce something that's secure. So
I don't want students going away from

32
00:02:42,640 --> 00:02:46,000
this course, thinking they know
how to store passwords safely,

33
00:02:46,000 --> 00:02:51,166
and getting fired because thousands of
customers' login credentials were stolen.

34
00:02:52,080 --> 00:02:56,800
So just in case you think I'm being overly
cautious, have a look at this Wikipedia entry. 

35
00:02:56,800 --> 00:03:02,513
You can see the link there, and it's in the resources
section. So I'll just load this up in a browser.

36
00:03:02,513 --> 00:03:06,560
You can see there, that the number of users' records
that have been stolen is staggering. There's some

37
00:03:06,560 --> 00:03:11,040
big names in that list, including Facebook,
Google and even the US Ministry of Defense.

38
00:03:12,880 --> 00:03:17,200
If your Twitter password is the same as your
GMail password, then an attacker can use the

39
00:03:17,200 --> 00:03:21,898
details they steal from Twitter to access your
email. And once they've gotten into your email,

40
00:03:21,898 --> 00:03:27,395
they can reset all the other passwords, using the
Forgotten password link that most websites have.

41
00:03:28,720 --> 00:03:32,160
So we're not going to show you how to
hash passwords. You'll need to learn a

42
00:03:32,160 --> 00:03:36,960
lot about computer security, before you
can safely attempt authentication code.

43
00:03:36,960 --> 00:03:41,760
What we will do, is see how to detect if a
file or an email message has been changed -

44
00:03:41,760 --> 00:03:48,960
including being tampered with. We'll write a short
program to demonstrate that, in the next video.

