The library

Keeping it safe

Store and check a password so that a stolen database is survivable, well enough to derive why each part of the standard recipe exists, to choose the cost parameter from your own hardware, and to migrate an old scheme without locking anybody out

How a Password Is Stored

Every part of the standard advice about passwords has a reason, and the reasons are derivable. This course works out what an attacker does with a stolen table, and builds the storage that makes it not worth doing.

8 lessons, written and corrected before you arrived. Reading them here needs no account. The first reads the whole way through; the others open and then stop, because a page nobody owns cannot tell who is reading it. Starting the course gives you your own copy, where every idea has problems standing under it and you can ask about any sentence.

Start reading

  1. 01The Only Thing the Table May HoldA password table has to let you check a password and must not let anybody recover one. Those two requirements are compatible, and only one kind of value satisfies both.
  2. 02The Number That Makes the Rest Necessaryopening onlyPut a real figure on how many guesses a rented machine makes per second against a fast one-way value, and every precaution in this course stops looking like ceremony.
  3. 03Two Rows That Look the Sameopening onlyIf two accounts chose the same password their stored rows are identical, and that one fact hands an attacker both a free census of your users and the whole precomputation industry.
  4. 04The One Place Slowness Is the Featureopening onlyOnce the attackers work is per account, the cost of one guess becomes the whole defence. Here is how to choose that cost from a measurement rather than from a number somebody posted.
  5. 05A Quarter of a Second, Ten Thousand Times at Onceopening onlyA repetition count costs processor time, and processor time is the one thing an attacker can buy in bulk. The answer is to demand something their hardware has little of: memory.
  6. 06The Comparison That Tells You How Close You Wereopening onlyVerification ends in a comparison of two values, and the obvious way to write it stops at the first byte that differs. That difference in time is an answer the attacker was not supposed to get.
  7. 07The Stored Row Was Never the Only Copyopening onlyA password arrives in plain text and travels through your system before it is ever hashed. Every stop it makes is a place it can stay, and most of them keep it longer than the database would.
  8. 08Upgrading Something You Cannot Readopening onlyYou decided on better settings and a better function. The rows you already have were written with the old one, you cannot read any of them, and nobody is going to reset forty thousand passwords.