Sitemap
Press enter or click to view image in full size
Photo by Towfiqu barbhuiya on Unsplash

Member-only story

Which Type of Encryption is Used for Protecting Passwords and Other Secrets in Windows?

2 min readJun 26, 2022

--

As you may know, with Windows 2000, Microsoft took security seriously and integrated the Data Protection Application Programming Interface (DPAPI). It has since become a core part of many applications including Windows Credential Manager, Internet Explorer, and Outlook. Overall, it provides a simple API to encrypt and decrypt data. These days it is often used to encrypt the master key and the private keys within public key pairs. A full analysis was performed by Burzstein and Picod [1]:

Press enter or click to view image in full size

In terms of the encryption methods, they found that it varied depending on the operating system version:

  • Windows 2000 uses RC4 and HMAC-SHA-1 with one round of PBKDF2. Approximate security strength: 95,000 passwords/second.
  • Window XP uses 3DES and HMAC-SHA-1 with 4000 rounds of PBKDF2. Approximate security strength: 4,000 passwords/second.
  • Windows Vista uses 3DES and HMAC-SHA-1 with 24000 rounds of PBKDF2. Approximate security strength: 12 passwords/second.
  • Windows 7 and Windows 10 use 256-bit AES-CBC and HMAC-SHA-512 with 5600 rounds of PBKDF2…

--

--

Prof Bill Buchanan OBE FRSE
Prof Bill Buchanan OBE FRSE

Written by Prof Bill Buchanan OBE FRSE

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.