Protecting password databases and users’ privacy is one of today’s most significant business challenges. Monthly, a new string of a corporate security breaches are in the headlines. In 2016, thousands of organizations experienced a data breach, each costing an average of $4 million or $158 per record of information. In addition to the direct cost, companies suffer significant damage to their reputation and experience higher than normal customer turnover following a data breach.
For the last 45 years, best practice has been to protect passwords by making each guess at the password expensive. However, once a password database is stolen, current encryption methods are easily defeated by cybercriminals.
BlindHash completely secures your passwords against offline attack, even if your password database is stolen. Our technology transforms a password hash into a lookup function over a massive pool of completely random data. The result of the lookup is used to decrypt the hash and allow the authentication process to complete. The BlindHash data pool acts as a "data anchor" since the entire data pool would need to be downloaded before an attacker could even begin the process of cracking a single password. The data pool is large enough that attempting to transfer the entire pool over the network would take years at full line rate.
Our patented cloud-based solution provides an additive layer of security that works in conjunction with your existing password defenses, systems and processes. You maintain complete control over your data, your users, and your authentication process, but have the peace of mind that comes from knowing your password database is virtually impossible to steal.