Lesson 3.210mIntermediate8.5k students
Password storage and hashing
Passwords are hashed with a slow, salted algorithm designed for the job. Anything faster is a favour to whoever steals the table.
This lesson sits in Authentication Done Right, part of Practical Web Security. It assumes what came before it and leads directly into the next lesson in the module.
In this lesson you will
- Use a slow, salted hash such as argon2 or bcrypt
- Tune work factors as hardware improves
- Handle reset flows without leaking account existence
Pro tip
Never write your own password hashing. Use a vetted algorithm with sane parameters and move on.
Resources
Your notes for this lesson will appear here.