4 ms·
It is however considered a good practice and recommended [1]. [1]: https://crackstation.net/hashing-security.htm https://crackstation.net/hashing-security.htm
by oxplot 11y ago
It is however considered a good practice and recommended [1].
[1]: https://crackstation.net/hashing-security.htm https://crackstation.net/hashing-security.htm
- e12e 11y agoSee my other comment re: "encrypted". In general terms, hashing a combination of a salt and the plaintext password is recommended. The problem with encrypting the password, is that typically an attack that exposes the encrypted password will also expose the encryption key -- allowing the recovery of the plaintext password by simply decrypting the ciphertext password that is stored.