# Password hashing

> Storing a one-way, salted, deliberately slow fingerprint of each password — so a stolen database is a puzzle, not a list.

A database of plaintext passwords is a breach that reaches every other service your users touch, because people reuse. Hashing makes verification possible without storage of the secret: you hash the attempt and compare. The algorithm matters — bcrypt, scrypt or Argon2 are designed to be expensive to guess; plain SHA-256 is not a password hash, just a fast one.

The salt defeats the shortcut: an identical per-password random value means two users with 'password1' get different hashes, so attackers cannot crack the whole table in one pass. 'We encrypt passwords' is the red flag — encryption is reversible by whoever holds the key; the point is that nobody should be able to get the password back.

## Related terms

- https://dfieldsolutions.com/en/glossary/mfa.md
- https://dfieldsolutions.com/en/glossary/encryption-at-rest.md
- https://dfieldsolutions.com/en/glossary/data-minimization.md

---

Source: https://dfieldsolutions.com/en/glossary/password-hashing
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
