DFIELDSOLUTIONS

Security

GlossaryPassword hashing

Storing a one-way, salted, deliberately slow fingerprint of each password — so a stolen database is a puzzle, not a list.

A database of plaintext passwords is a breach that reaches every other service your users touch, because people reuse. Hashing makes verification possible without storage of the secret: you hash the attempt and compare. The algorithm matters — bcrypt, scrypt or Argon2 are designed to be expensive to guess; plain SHA-256 is not a password hash, just a fast one.

The salt defeats the shortcut: an identical per-password random value means two users with 'password1' get different hashes, so attackers cannot crack the whole table in one pass. 'We encrypt passwords' is the red flag — encryption is reversible by whoever holds the key; the point is that nobody should be able to get the password back.

Related terms

The bench this belongs to

Cybersecurity

Purple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.

All termsStart a conversationMarkdown version

DField Bt. · Dunakeszi · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain