Password Hashing
The practice of storing passwords as the output of a slow, salted, one-way function rather than as plain text or reversible encryption, so that a stolen database does not directly reveal users' passwords.
When a user sets a password, the system generates a unique random salt, combines it with the password and passes the result through a password hashing function; only the salt, the algorithm parameters and the resulting hash are stored. At login the same computation is repeated and the results compared. Salts ensure that identical passwords produce different hashes and defeat precomputed rainbow tables, while deliberately slow, tunable algorithms make large-scale guessing expensive.
Recommended algorithms are designed specifically for passwords: Argon2id, from the Argon2 family that won the Password Hashing Competition, scrypt, bcrypt and PBKDF2, the last being the usual choice where FIPS-validated cryptography is required. General-purpose hash functions such as MD5, SHA-1 or a single round of SHA-256 are unsuitable because they are fast enough for attackers with GPUs to test enormous numbers of guesses. Weak password storage falls under cryptographic failures in the OWASP Top 10 2021.
Work factors should be tuned so that hashing takes a noticeable but acceptable time on the server, and increased as hardware improves, with stored hashes upgraded at the next login. An optional secret pepper kept separately from the database adds protection. Hashing does not protect weak or reused passwords on its own, so it is combined with MFA, checks against known breached passwords and rate limiting, as recommended in NIST SP 800-63B.
Key points
- Passwords are stored as salted, slow, one-way hashes, never as plain text.
- Argon2id, scrypt, bcrypt and PBKDF2 are designed for password storage.
- Fast hashes such as MD5 or SHA-1 are unsuitable for passwords.
- Work factors should increase over time as hardware gets faster.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.