Learning path

Full curriculum

Full curriculum

Unit content

Password hashing, salts and offline guessing

A server that authenticates passwords should not need to store the original password.

Instead it stores the output of a password-hashing function together with a random salt:

$$h=\operatorname{PasswordHash}(\text{password},\text{salt}).$$

On login, the server recomputes the function using the stored salt and compares the result.

The salt does not need to be secret. Its purpose is to make equal passwords produce different stored values and to prevent one precomputed table from efficiently attacking many accounts at once.

Password hashing should be deliberately expensive in time and, for modern schemes, often memory. If a password database is stolen, the attacker can test guesses offline without rate limits; making each guess costly directly slows that attack.

A general fast cryptographic hash is not a substitute for a password-hashing scheme designed for this purpose. Password security depends both on the user's secret and on how expensive offline verification is made for an attacker.