Roger Needham
- Co-authored the Needham-Schroeder authentication protocol (1978)
- Pioneered storing passwords as one-way hashes rather than plaintext
- Led the Cambridge Computer Laboratory and founded Microsoft Research Cambridge
Bio
Roger Needham (1935 to 2003) led the Cambridge Computer Laboratory and founded Microsoft Research Cambridge. With Michael Schroeder he published "Using Encryption for Authentication in Large Networks of Computers" in 1978, and he is credited with the practice of storing passwords as one-way hashes rather than in recoverable form.
Profile built from public academic and institutional records.
Where their work shows up
Two ideas from one career sit under most of modern identity. Hashing passwords instead of storing them is why a database breach is a serious incident rather than an immediate total compromise, and why the argument today is about which hash and how it is salted rather than whether to hash at all. The authentication protocol became Kerberos. See credential stuffing and infostealer credential harvesting for what happens when the stored form is weak or bypassed.
Related on Start with Identity
- ExpertCo-author of the Needham-Schroeder protocol
Michael D. Schroeder co-authored two of the foundational papers in this field within three years of each other: the 1975 design-principles paper with Jerome Sal
- ExpertCo-author of the NIST RBAC model
David Ferraiolo co-authored "Role-Based Access Controls" with Rick Kuhn, presented at the 15th National Computer Security Conference in October 1992. The NIST m
- ExpertCo-author of the NIST RBAC model
Rick Kuhn co-authored the 1992 NIST paper on role-based access control with David Ferraiolo and has worked on the model, its formalization, and its assurance ev