1. Executive Summary & Scope
Cryptographic Failures regarding credential storage occur when systems hash user passwords using outdated, fast hashing algorithms (MD5, SHA-1, SHA-256) or insufficient work factors. Fast hashes allow attackers possessing a database dump to compute billions of guesses per second using commercial GPU cracking rigs.
2. Threat Model & Attack Vectors
Adversaries compromise the backend database and recover plaintext user and administrator passwords within hours using rainbow tables and offline GPU dictionary attacks.
3. Code Analysis & Remediation Playbook
Vulnerable Implementation Pattern
Hardened Defense-in-Depth Implementation
4. Audit Verification Checklist & Pass Criteria
| Verification Phase | Audit Test Description | Mandatory Passing Criteria |
|---|---|---|
| Database Hash Inspection | Extract sample hashes from test database to verify prefix patterns. | All active password hashes begin with `$argon2id$` or `$2y$12$`. Zero MD5/SHA hashes exist. |
| Timing Side-Channel Protection | Verify password comparison executes using constant-time string functions. | Verification prevents timing attacks regardless of input length. |
| Work Factor Benchmark | Measure hashing computation duration on production server hardware. | Hash generation takes between 250ms and 500ms to balance security and server throughput. |
WebOTG Application Security Directorate
WebOTG provides benchmark reference documentation, automated matrix evaluators, and security test harnesses for government digital platforms, WQMS architectures, and STQC compliance frameworks.