
teissTalk Host Geoff White was joined by Jake Davis, Hacking and hacker culture expert; Felipe Garcia, Chief Information Security Officer, Scotiabank; David Cartwright, Head of IT Security, Standard Bank International Client Solutions and Richard Archdeacon, Advisory CISO, Duo.
What is wrong with passwords?
Despite Bill Gates’s verdict on passwords in 2004 that they are ill-suited to the purpose they are to serve, seventeen years later we’re still having discussions on how their vulnerabilities and the complexities of how we use them can be mitigated. Although there is a lot of talk about how often passwords need to be changed, a more relevant question seems to be how a company stores them. One of the tools that can beef up passwords is hashing. Fast hashing can remove the fangs of even the strongest password, and the deepest encryption will be useless with passwords such as 1234.
Two breaches from 2014 clearly demonstrate the importance of strong hashing. The two victims were a professional networking platform and a file sharing service using Sha1 and bcrypt hashing, respectively. The first one had 98 per cent of its public data stolen, the latter only 10 per cent. Bcrypt always hashes every password with salt – adding random data to the input of a hashing function that makes each password hash unique. Meanwhile, sha1, with speedier calculations, is less secure and therefore brute-force attacks have bigger success with it. Generally speaking, a company does an excellent job with passwords and hashing if, once its passwords get out into the public domain, they can stay there for five years with less than 20 per cent of them being cracked. Deep and slow hashing is key to security, given that a standard laptop can crack hashes at a 200 billion per second rate, while, with a modest investment, you can easily get three times this speed. Even well-encrypted corporate passwords can fall victim to password spraying and credential stuffing if employees use the same password for external applications. Also, criminals subscribed to an “as-a-Service” model can commission hackers to crack passwords for them in a distributed manner, while by running AI through a multitude of passwords, they can also identify patterns of how people create them and leverage this information to make their hacking more efficient.

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543