Offizielles MASTR Logo MASTR Arbeit unterstützen
Inhalt
← Wiki-Startseite

Web-Grundlagen

Password storage: why hashing and encryption serve different jobs

A login service usually needs to verify a password, not recover its original text.

Security foundation · 1 min read

Rechercheartikel und Referenzeinträge erscheinen auf Englisch. Die Navigation ist in sieben Sprachen verfügbar.

In diesem Artikel
  1. Verification without plaintext
  2. A database leak changes the attack
  3. Quellen und Originale

Verification without plaintext

Password hashing transforms a supplied password into a value used for later comparison. A suitable password-hashing scheme deliberately makes repeated guesses expensive. Unique salts prevent identical passwords from automatically producing identical stored values and reduce the usefulness of precomputed tables.

General-purpose fast hashes are not a substitute for a password-hashing design. Work and memory parameters matter, as does their adjustment to the service's threat model and capacity. A scheme name without deployed parameters is incomplete evidence.

A database leak changes the attack

When hashes leak, attackers may test guesses offline without the service's ordinary login rate limits. Long, unique passwords reduce the usefulness of reuse and common guessing patterns. Server-side rate limiting remains valuable for online attacks, but it cannot govern a copied database.

Password storage also differs from an encrypted vault that must later decrypt user data. A review needs to examine key derivation, recovery and data encryption separately. Never infer that a product safely stores secrets from the word encrypted alone. Continue with custody and recovery dependencies.

Quellen und Originale

Weiterlesen

MASTR

Unabhängige Recherche unterstützen

Die Untersuchungen, Originalbelege und Anleitungen hier sind frei zugänglich. Freiwillige Spenden finanzieren die Recherche mit und helfen, die MASTR-Tools weiterhin anzubieten.

Wallet öffnen