Lazo Lab Sign up

Guides

Passwords, hashing and 2FA

Beginner 路 6 min read

How sites store passwords, why length beats complexity, and why two-factor matters.

Sites shouldn't know your password

A well-built site stores a hash of your password: a one-way fingerprint. When you log in, it hashes what you typed and compares fingerprints. This site does exactly that.

Good password hashes are deliberately slow and salted. Salt is random data added to each password so two people with the same password get different hashes.

Length beats complexity

Each extra character multiplies the number of guesses an attacker needs. Four random words like 'lamp river cactus orbit' are easier to remember and far harder to crack than 'P@ssw0rd1'.

Try both in the password lab on the home page and compare the times.

Never reuse passwords

When one site is breached, attackers try the leaked passwords everywhere else. A password manager lets you use a different random password on every site while remembering only one.

Two-factor login

Two-factor (2FA) adds a second proof, usually a code from an app like Google Authenticator or Authy. A stolen password alone is no longer enough. App codes are safer than text messages, which can be hijacked by SIM swapping.

Try it

Generate a strong password with Python, then turn on 2FA for your email account.

import secrets
import string

chars = string.ascii_letters + string.digits + "!@#$%-_"
print("".join(secrets.choice(chars) for _ in range(18)))