How Passwords Are Stored and Cracked
Every breach headline about 'leaked passwords' is really a story about hashes. This exercise explains what a hash is, why a stolen hash is not instantly a stolen password, how attackers crack hashes anyway, and the two choices — salting and a slow algorithm — that decide whether a leak is a minor event or a catastrophe.
Log in or create a free account to submit keys and track your progress.
What you will learn
- Explain what a hash is and why it is one-way
- Explain why sites store hashes instead of passwords
- Explain how a rainbow table cracks unsalted hashes
- Explain why salting and a slow hash (bcrypt/argon2) defeat cracking
In this exercise
- A one-way fingerprint
- Why sites store hashes
- How hashes get cracked anyway
- Salt: make every hash unique
- Slow by design: bcrypt and argon2
🔒
This is a Pro exercise
Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.
See Pro plans Create a free account5 sections · 2 keys · 50 points