Member-only story
Which Type of Encryption is Used for Protecting Passwords and Other Secrets in Windows?
As you may know, with Windows 2000, Microsoft took security seriously and integrated the Data Protection Application Programming Interface (DPAPI). It has since become a core part of many applications including Windows Credential Manager, Internet Explorer, and Outlook. Overall, it provides a simple API to encrypt and decrypt data. These days it is often used to encrypt the master key and the private keys within public key pairs. A full analysis was performed by Burzstein and Picod [1]:
In terms of the encryption methods, they found that it varied depending on the operating system version:
- Windows 2000 uses RC4 and HMAC-SHA-1 with one round of PBKDF2. Approximate security strength: 95,000 passwords/second.
- Window XP uses 3DES and HMAC-SHA-1 with 4000 rounds of PBKDF2. Approximate security strength: 4,000 passwords/second.
- Windows Vista uses 3DES and HMAC-SHA-1 with 24000 rounds of PBKDF2. Approximate security strength: 12 passwords/second.
- Windows 7 and Windows 10 use 256-bit AES-CBC and HMAC-SHA-512 with 5600 rounds of PBKDF2…
