May 20, 2015 By Shane Schick 2 min read

Cybercriminals use a lot of deceptive tricks to break into corporate systems, which makes a fake password project seem not only ingenious, but a sort of sweet revenge for beleaguered IT security staff.

IDG News Service, which first published a story about the scheme on sites such as InfoWorld, said the ErsatzPasswords program, as it is known, is the brainchild of a group of researchers from the Purdue University. It is not a completed project but an idea to be discussed at a security conference by one of its creators, Mohammed H. Almeshekah. Essentially, the fake password project describes a way of adding an element to a password via hardware before it is encrypted. As a result, cybercriminals who try to break into a leaked database would be presented with fake passwords, which would take them time to work through before they realize they’ve been duped.

As Effect Hacking noted, source code for ErsatzPasswords is already available for review on Github and takes advantage of the “hash,” or algorithms used to encrypt passwords, by using a “salt,” or extra value created for a service. Unless cybercriminals could get access to the module that was part of the ErsatzPassword process, it is unlikely they would find a way to get full access to a system without some brute-force type of attack. In other words, even if the Purdue researchers’ idea doesn’t completely protect corporate data, the fake password project could make it a lot harder for cybercriminals to steal data or do other kinds of damage.

Of course, malicious attackers are not without their resources and typically use third-party services to get lists of commonly used passwords to make their lives easier. But according to forensic security consulting firm LIFARS, the ErsatzPasswords fake password project would not only make such lists relatively useless, it could also allow network administrators to set up alerts when someone tries to use a fake password to hack into a compromised database. That might enable enterprises to take action before critical information winds up in the wrong hands.

The potential for passwords to be discovered or used against organizations has risen in recent years, to the point where some experts have suggested doing without them entirely. A PayPal executive, for example, recently suggested biometric identifiers might one day offer a compelling and safer alternative, even to encrypted passwords. Until then, it might be worthwhile for IT departments to consider whether ErsatzPasswords could be layered onto their existing security practices — if only because it might make cybercriminals’ lives a little more miserable.

More from

FYSA — VMware Critical Vulnerabilities Patched

< 1 min read - SummaryBroadcom has released a security bulletin, VMSA-2025-0004, addressing and remediating three vulnerabilities that, if exploited, could lead to system compromise. Products affected include vCenter Server, vRealize Operations Manager, and vCloud Director.Threat TopographyThreat Type: Critical VulnerabilitiesIndustry: VirtualizationGeolocation: GlobalOverviewX-Force Incident Command is monitoring activity surrounding Broadcom’s Security Bulletin (VMSA-2025-0004) for three potentially critical vulnerabilities in VMware products. These vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, have reportedly been exploited in attacks. X-Force has not been able to validate those claims. The vulnerabilities…

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today