Quantcast
Channel: What is a good analogy to explain to a layman why passwords should be hashed? - Information Security Stack Exchange
Viewing all articles
Browse latest Browse all 19

Answer by GdD for What is a good analogy to explain to a layman why passwords should be hashed?

$
0
0

I like analogy as a way to explain technology, however in this case it's probably not workable as the analogy would be too complex.

Most managers are more motivated to avoid personal risk to their position than doing the right thing, so rather than an analogy I'd use examples where storing passwords in plain text has reflected badly on a company. I'd just say something like

"Storing passwords in plain text would make us look very bad, risking our reputation and possibly opening ourselves up to litigation. It is considered very bad practice in any industry, and there are websites devoted to naming and shaming companies that store passwords in the clear. Personally, I wouldn't like to be the one standing in front of the board/boss/CTO explaining why we didn't put a basic security control in place. If we hash our customer's passwords a data breach wouldn't cause an immediate leak of passwords hackers could use, and we would be seen to be protecting our customers' information. Hashing passwords mitigates a big risk for little effort. "

Include with it links to Plain Text Offenders, and then send likes to some news stories like Cupid Media, Microsoft India Store, etc.


Viewing all articles
Browse latest Browse all 19

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>