HomeHow ToPassword Hashing: A Beginner's Guide

Password Hashing: A Beginner's Guide

HashingHashing process that allows someone to ensure that their password is secure and cannot be recovered by hackers. Hashing algorithms are one-way. They take a password and convert it into a “fingerprint” of a fixed length. The hashed password cannot be easily decrypted. Essentially, this process is similar to encryption. So if a hacker compromises a system, they will not be able to access the password.

Many sites use this method to secure their users' passwords.

The process is as follows:

  • Initially, the user creates an account.
  • Then, the password is hashed and stored in the database.
  • When the user attempts to log in to the site, the hash of the password they entered is compared to the stored password and if they match, the user is logged in normally. Otherwise, a general message appears saying that there was an error in the credentials, without specifically stating whether the error was detected in the username or password, in order to make it more difficult for would-be hackers.

HashingAttacks to "break" hashes

Brute Force and Dictionary attacks

A Brute Force attack tries all possible character combinations, with a certain length. This means that at some point the password will definitely be cracked. However, it is not an easy process. Even very short passwords can take thousands of years (literally) to crack through a Brute Force attack, since the hacker has no way of knowing when he will hit the right character combination.

Dictionary attacks use a file containing common words, phrases, or passwords that someone might have used as a password. Hackers have access to databases containing the top 100,000 (or more) passwords. The attack hashes these passwords and compares the hash to the password they want to crack. This is a faster method than a brute force attack.

However, there is another process, known as "salting", which prevents these attacks more effectively.

Password Hashing: A Beginner's Guide

Salting

The reason why the above attacks can be used and are effective is that hashing is always done the same way. It is possible to randomize the hashingby adding a random string, called a salt, to the passwords BEFORE hashing.

What to do and what not to do in the salting process:

First, what not to do:

  • not use the same salt for all passwords
  • not use short salt lengths.
  • not use strange double hashes (e.g.: hash (hash (hash ('mypass'))))

What should we do:

  • We must generate random salts with the help of special programs (Cryptographically Secure Pseudo-Random Number Generator-CSPRNG)
  • We need to generate a new unique random salt for each password
  • We need to create long salts

The salting process is as follows:

  • First, we create a very large salt with the help of a CSPRNG
  • Next, we add the salt to the code and then hash it
  • We store the salt and hash in the database

Password check:

  • Get the salt and hash from the database
  • Add the salt to the submitted code and hash it
  • Compare the hashes. If they are the same, the password is correct
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS