Passwords, hashing and 2FA
Beginner 路 6 min read
How sites store passwords, why length beats complexity, and why two-factor matters.
Sites shouldn't know your password
A well-built site stores a hash of your password: a one-way fingerprint. When you log in, it hashes what you typed and compares fingerprints. This site does exactly that.
Good password hashes are deliberately slow and salted. Salt is random data added to each password so two people with the same password get different hashes.
Length beats complexity
Each extra character multiplies the number of guesses an attacker needs. Four random words like 'lamp river cactus orbit' are easier to remember and far harder to crack than 'P@ssw0rd1'.
Try both in the password lab on the home page and compare the times.
Never reuse passwords
When one site is breached, attackers try the leaked passwords everywhere else. A password manager lets you use a different random password on every site while remembering only one.
Two-factor login
Two-factor (2FA) adds a second proof, usually a code from an app like Google Authenticator or Authy. A stolen password alone is no longer enough. App codes are safer than text messages, which can be hijacked by SIM swapping.
Try it
Generate a strong password with Python, then turn on 2FA for your email account.
import secrets
import string
chars = string.ascii_letters + string.digits + "!@#$%-_"
print("".join(secrets.choice(chars) for _ in range(18)))