Author: emmanuelygr
Password Security Lab is an interactive command-line application built in Python that demonstrates core concepts of modern password security. The tool provides a hands-on learning environment for understanding how passwords are safely processed, evaluated, and stored using industry-standard hashing techniques.
This project was developed to provide a practical understanding of cybersecurity fundamentals, specifically focusing on authentication and password management. Many data breaches occur due to poor password storage practices (like storing passwords in plain text or using weak hashing algorithms without salts). Building this tool demonstrates how to implement secure password handling and evaluate password strength properly.
- Hashing: Understand how to convert a plain-text password into a secure hash.
- Salting: Learn the importance of adding random data to passwords before hashing to defend against rainbow table attacks.
- Verification: Grasp how to verify user input against a stored hash without ever knowing the actual password.
- Authentication: Build a basic user registration and login flow.
- Password Strength Evaluation: Analyze passwords for length, complexity, and character variety.
- Account Creation: Register new users with strong password recommendations.
- Authentication: Secure login system comparing input against stored hashes.
- Password Strength Checker: Evaluate password complexity with actionable feedback.
- Secure Storage: Passwords are never saved in plain text; they are hashed and salted using bcrypt.
- Python 3.x: Core programming language.
- bcrypt: Industry-standard library for secure password hashing.
- JSON: Lightweight data interchange format for simulating a database (
users.json). - re (Regular Expressions): For evaluating password complexity.
A plaintext password is the exact string a user types (e.g., Password123!). Storing this is highly insecure. A hash is a cryptographic function that transforms the plaintext into a fixed-length, unpredictable string. Unlike encryption, hashing is a one-way process; you cannot reverse a hash back to the plaintext.
A salt is random data added to a password before hashing. If two users have the same password, they will have the same hash without salting. This makes them vulnerable to pre-computed attacks (Rainbow Tables). A salt ensures that even identical passwords produce entirely different hashes.
Authentication is the process of proving a user's identity. During login, the system takes the provided password, applies the same salt and hash function used during registration, and compares the resulting hash with the stored hash. If they match, the user is authenticated.
A strong password is computationally harder to crack through brute force or dictionary attacks. Evaluating password strength involves checking:
- Length: Longer passwords exponentially increase the time needed to crack.
- Complexity: Utilizing a mix of uppercase, lowercase, numbers, and special characters expands the possible character set.
- Registration: User enters a username and password. The system evaluates the password strength and provides feedback. It then generates a salt, hashes the password using
bcrypt, and stores the username and the resulting hash inusers.json. - Login: User enters credentials. The system retrieves the hash for the username, extracts the salt, hashes the entered password, and compares the results.
- Strength Check: Uses regex to determine if the password meets security criteria (uppercase, lowercase, digits, special characters, length >= 8).
password-security-lab/
│
├── password_lab.py # Main application logic
├── requirements.txt # Python dependencies
├── users.json # Local JSON database (created after first user)
├── .gitignore # Git ignore configuration
├── LICENSE # MIT License
└── README.md # Project documentation
-
Clone the repository (or download the files):
git clone <repository_url> cd password-security-lab
-
Set up a virtual environment (recommended):
python -m venv venv source venv/bin/activate # On Windows use: venv\Scripts\activate
-
Install dependencies:
pip install -r requirements.txt
Run the main script:
python password_lab.pyFollow the on-screen menu:
=== Password Security Lab ===
1. Create Account
2. Authenticate
3. Check Password Strength
4. Exit
Choose an option:
--- Create Account ---
Enter a new username: alice
Enter a password: password
Password Strength: Weak
- Add uppercase letters.
- Add numbers.
- Add special characters (!@#$%).
Warning: We strongly recommend using a stronger password.
Hashing password securely...
Account created successfully!
--- Authenticate ---
Username: alice
Password: password
Authentication successful! Welcome, alice
Enter a password to test: SuperS3cr3t!
Password Strength: Strong
- Local Storage: This project uses a local
users.jsonfile to store credentials for educational purposes. In a production environment, you would use a secure, scalable database. - bcrypt Work Factor: The
bcryptlibrary uses a default work factor (rounds) to ensure hashing is slow enough to thwart brute-force attacks. This can be adjusted based on hardware capabilities.
This tool is for educational purposes only. It is designed to teach defensive security concepts. Do not use this tool or its concepts to attempt unauthorized access to systems, intercept communications, or process real user data in production without proper security reviews.
- In-Memory/File Storage:
users.jsonis not a secure database and is prone to file corruption or unauthorized local access. - No Rate Limiting: The current implementation does not limit login attempts, leaving it vulnerable to automated brute-force attacks.
- No Password Recovery: There is no mechanism to reset a forgotten password.
Q: I get a ModuleNotFoundError: No module named 'bcrypt' error.
A: Ensure you have installed the requirements using pip install -r requirements.txt. If you are using a virtual environment, make sure it is activated.
Q: Where are the passwords stored?
A: They are stored as bcrypt hashes inside users.json in the same directory. The file is created automatically when the first user registers.
- Implementing secure password hashing in Python using
bcrypt. - The practical difference between encryption and hashing.
- Designing a rudimentary authentication flow.
- Using regular expressions to validate and evaluate string patterns.
- Implement Rate Limiting: Add a delay or lockout mechanism after multiple failed login attempts to prevent brute-force attacks.
- Database Integration: Migrate from
users.jsonto a robust database like SQLite or PostgreSQL. - Password Policies: Enforce strict password policies during registration rather than just providing warnings.
- Multi-Factor Authentication (MFA): Introduce a secondary authentication step (e.g., OTP via email or authenticator app).
- Session Management: Implement a secure session token system to keep users logged in across actions.
- GUI Integration: Build a graphical user interface using Tkinter or a web framework like Flask/Django.