Password hashing question

36 views
Skip to first unread message

Mally Mclane

unread,
Aug 1, 2011, 4:06:53 AM8/1/11
to google-app...@googlegroups.com
Dear list members,

Following on from my question last week, maybe a question for one of
the resident Google employees :)


We are intending to set passwords through the Google Apps Provisioning
API, sending (probably) the SHA-1 hash. We've been asked by the
University's security officer to clarify whether Google stores the
hash that we send, or whether it has further "salting"/encryption
applied beforehand?


Mally

Michael Manoochehri

unread,
Aug 1, 2011, 7:44:14 AM8/1/11
to google-app...@googlegroups.com
Hi Mally:

This is a great question.

No, we don't store the exact cryptographically hashed password you provide when creating or updating a user. The value we end up storing does use additional salting, as well as other one way transformations to provide a very secure result.

- Michael

Mally Mclane

unread,
Aug 1, 2011, 7:45:45 AM8/1/11
to google-app...@googlegroups.com

Michael,

Again, thankyou!

> --
> You received this message because you are subscribed to the Google Groups "Google Apps Domain Information and Management APIs" group.
> To view this discussion on the web visit https://groups.google.com/d/msg/google-apps-mgmt-apis/-/Fp0d9GT8isIJ.
> To post to this group, send email to google-app...@googlegroups.com.
> To unsubscribe from this group, send email to google-apps-mgmt...@googlegroups.com.
> For more options, visit this group at http://groups.google.com/group/google-apps-mgmt-apis?hl=en.
>

Mally Mclane

unread,
Aug 4, 2011, 6:50:11 AM8/4/11
to google-app...@googlegroups.com
Michael,

> No, we don't store the exact cryptographically hashed password you provide
> when creating or updating a user. The value we end up storing does use
> additional salting, as well as other one way transformations to provide a
> very secure result.

Further to this.. do you have any plans to allow customers to supply
hashes in any stronger alternatives to SHA-1? Eg SHA-2, or SHA-3 when
the winner of the the NIST hash function competition is announced?

Mally

Michael Manoochehri

unread,
Aug 8, 2011, 1:36:48 PM8/8/11
to google-app...@googlegroups.com
Hi Mally:

As far as I know, we don't have any plans to add the ability to create users with passwords processed with other cryptographic hashing algorithms besides SHA-1 and MD5. However, it would be great idea if you could add this feature request to our public issue tracking list:
- Michael
Reply all
Reply to author
Forward
0 new messages