Lazo Lab Sign up

Cryptography / Hashing

Lesson 9 of 25

Hashing passwords

Password hashes must be slow and salted so guessing is expensive. bcrypt, scrypt and Argon2 are designed for this; SHA-256 alone is too fast.

Key points

  • Salt: random data per password
  • Slow: thousands of rounds
  • Argon2 won the Password Hashing Competition
Watch a video on thisOpens YouTube search results for “Hashing passwords” in a new tab

Quiz · +10 XP

Why add a salt to a password hash?

Log in to save progress and earn XP.