How Passwords Are Stored and Cracked

🔒 Pro Medium Course Online Avg. time 30 min Solved by 0 2 keys · 50 pts Access & Authentication

Every breach headline about 'leaked passwords' is really a story about hashes. This exercise explains what a hash is, why a stolen hash is not instantly a stolen password, how attackers crack hashes anyway, and the two choices — salting and a slow algorithm — that decide whether a leak is a minor event or a catastrophe.

Skills covered: CryptographyPasswords
Log in or create a free account to submit keys and track your progress.

What you will learn

  • Explain what a hash is and why it is one-way
  • Explain why sites store hashes instead of passwords
  • Explain how a rainbow table cracks unsalted hashes
  • Explain why salting and a slow hash (bcrypt/argon2) defeat cracking

In this exercise

  1. A one-way fingerprint
  2. Why sites store hashes
  3. How hashes get cracked anyway
  4. Salt: make every hash unique
  5. Slow by design: bcrypt and argon2
🔒

This is a Pro exercise

Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.

See Pro plans Create a free account

5 sections · 2 keys · 50 points