Why doesn't your favorite website know your password?
A well-built website can check your password without ever knowing it. In the 1970s, Unix even let everyone read the file of scrambled passwords.
▶ Start the storyA well-built website never stores your password. It stores a hash: a fixed-length jumble of characters made by running your password through a one-way mathematical function. The function is quick to compute forwards but practically impossible to run backwards, so nobody, not even the website, can turn the hash back into your password. When you log in, the site runs what you typed through the same function and checks whether the two hashes match.
Hashes are also touchy: change a single letter of the input and the output looks completely different, so near misses give nothing away.

Two extra tricks make stolen hashes much less useful. The first is a salt, a random value generated for each account and mixed with the password before hashing. Without it, everyone who chose the same password would have the same hash, and attackers could look them up in huge precomputed tables. The second is slowness: password hashing is deliberately made slow, so an attacker who steals a database can only try a limited number of guesses per second.
These ideas are older than the web. In the 1970s, Unix computers kept salted password hashes in a file that every user could read, trusting the one-way function to do its job. In 1978 Robert Morris invented crypt, the first deliberately slow password hash. Faster computers eventually made it crackable, which is why today's systems keep getting slower on purpose.
Quiz me
0/3
Recap
Sites store a salt and a slow hash, never your password: logging in means matching hashes.
Surprising fact · Password hashing is deliberately slow, to throttle attackers' guesses.
Sources (4)
No source, no claim. Every fact in this lesson (16 claims) cites at least one of these.