2 ms·
There are considerations on the performance as well. Usually, a responsible website will password-hash the plain-text password into a hashed string before savi
by nirui 4y ago
There are considerations on the performance as well.
Usually, a responsible website will password-hash the plain-text password into a hashed string before saving the hashed string into their storage. Password-hash is a special hashing process designed to be reasonability slow, so an attacker who somehow obtained the hashed string cannot easily collide the hash with another plain-text.
Some password-hash configuration can took few milliseconds to run, that's really expensive if you have to do that for every request just so you can compare the client password-hash v.s. the one stored on your server.
(Full disclosure, I designed few session manage systems for my job before :D)
- mooreds 4y agoThat's a great point. Hashing makes it more painful to credential stuff. I had a colleague write a few thousand words on the topic: https://fusionauth.io/learn/expert-advice/security/math-of-password-hashing-algorithms-entropy https://fusionauth.io/learn/expert-advice/security/math-of-p...