Tech●●●●●Difficulty 2 of 5

Why doesn't your favorite website know your password?

A well-built website can check your password without ever knowing it. In the 1970s, Unix even let everyone read the file of scrambled passwords.

▶ Start the story

A well-built website never stores your password. It stores a hash: a fixed-length jumble of characters made by running your password through a one-way mathematical function. The function is quick to compute forwards but practically impossible to run backwards, so nobody, not even the website, can turn the hash back into your password. When you log in, the site runs what you typed through the same function and checks whether the two hashes match.

Hashes are also touchy: change a single letter of the input and the output looks completely different, so near misses give nothing away.

Diagram showing several short input texts, including almost identical ones, each passing through a hash function and producing completely different strings of characters.
A hash function at work: inputs that differ by a single word or letter come out as completely different digests, and the digests can't be turned back into the inputs.Photo: User:Jorge Stolfi based on Image:Hash_function.svg by Helix84 · Public domain

Two extra tricks make stolen hashes much less useful. The first is a salt, a random value generated for each account and mixed with the password before hashing. Without it, everyone who chose the same password would have the same hash, and attackers could look them up in huge precomputed tables. The second is slowness: password hashing is deliberately made slow, so an attacker who steals a database can only try a limited number of guesses per second.

These ideas are older than the web. In the 1970s, Unix computers kept salted password hashes in a file that every user could read, trusting the one-way function to do its job. In 1978 Robert Morris invented crypt, the first deliberately slow password hash. Faster computers eventually made it crackable, which is why today's systems keep getting slower on purpose.

Quiz me

0/3

  1. 1.What does a website actually store in its database after you create a password?
  2. 2.What is the primary security purpose of adding a 'salt' to a password before hashing it?
  3. 3.Why do security systems intentionally use slow hashing algorithms for passwords?

Recap

Sites store a salt and a slow hash, never your password: logging in means matching hashes.

Surprising fact · Password hashing is deliberately slow, to throttle attackers' guesses.

Sources (4)

No source, no claim. Every fact in this lesson (16 claims) cites at least one of these.

  1. [1]Key derivation function · Wikipedia
  2. [3]Salt (cryptography) · Wikipedia
  3. [4]Cryptographic hash function · Wikipedia
  4. [5]Rainbow table · Wikipedia
More lessons in 💻 Tech (3) See all tech lessons →

One more light on your map.

Get one lesson like this every day, about the things you love. Free, in two or five minutes.

Get the share card for this lesson ↗