Lesson 3.210mIntermediate8.5k students

Password storage and hashing

Passwords are hashed with a slow, salted algorithm designed for the job. Anything faster is a favour to whoever steals the table.

This lesson sits in Authentication Done Right, part of Practical Web Security. It assumes what came before it and leads directly into the next lesson in the module.

In this lesson you will

  • Use a slow, salted hash such as argon2 or bcrypt
  • Tune work factors as hardware improves
  • Handle reset flows without leaking account existence

Pro tip

Never write your own password hashing. Use a vetted algorithm with sane parameters and move on.

Resources