Store and check a password so that a stolen database is survivable, well enough to derive why each part of the standard recipe exists, to choose the cost parameter from your own hardware, and to migrate an old scheme without locking anybody out
How a Password Is Stored

Every part of the standard advice about passwords has a reason, and the reasons are derivable. This course works out what an attacker does with a stolen table, and builds the storage that makes it not worth doing.
8 lessons, written and corrected before you arrived. Reading them here needs no account. The first reads the whole way through; the others open and then stop, because a page nobody owns cannot tell who is reading it. Starting the course gives you your own copy, where every idea has problems standing under it and you can ask about any sentence.