Hashing and Salting of Passwords
Matthew McGiffen · Apress eBooks · 2022
In this chapter we’re going to look at how you should go about securely storing passwords in your database. In most cases these will be passwords related to user logons for your application. In many ways a password is the most sensitive piece of information that we might store. If a user’s password is obtained by an attacker, then it is likely they can access all of the other information we hold about a user. Worse than that, despite recommendations to the contrary, most users reuse the same password across multiple services that they use. That means that if their password is breached in our application, then that may give an attacker access to accounts the user holds with other organizations.