Case 2D27C6 · Cryptography · L2 Practitioner
Salting, bcrypt and Argon2
Practise as: Explain it · Interview
Interview questionHow should an application store user passwords, and why?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Never encrypt or plain-hash passwords; use a slow, salted password hash: Argon2id (preferred), scrypt, bcrypt.
- A unique random salt per user defeats rainbow tables and makes identical passwords hash differently.
- Work factors (bcrypt cost, Argon2 memory/iterations) slow GPU cracking; Argon2id is memory-hard against ASICs.
- bcrypt truncates input at 72 bytes; PBKDF2 with high iterations is the FIPS-friendly choice.
- Optional pepper (secret in HSM/KMS, not in DB) adds protection if only the database leaks; rehash on login to upgrade.
If the interviewer pushes back
- How would you migrate 10 million legacy unsalted MD5 hashes to Argon2id without forcing resets?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.