Open cardosec

Case 2D27C6 · Cryptography · L2 Practitioner

Salting, bcrypt and Argon2

Practise as: Explain it · Interview

Interview questionHow should an application store user passwords, and why?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Never encrypt or plain-hash passwords; use a slow, salted password hash: Argon2id (preferred), scrypt, bcrypt.
  2. A unique random salt per user defeats rainbow tables and makes identical passwords hash differently.
  3. Work factors (bcrypt cost, Argon2 memory/iterations) slow GPU cracking; Argon2id is memory-hard against ASICs.
  4. bcrypt truncates input at 72 bytes; PBKDF2 with high iterations is the FIPS-friendly choice.
  5. Optional pepper (secret in HSM/KMS, not in DB) adds protection if only the database leaks; rehash on login to upgrade.

If the interviewer pushes back

  • How would you migrate 10 million legacy unsalted MD5 hashes to Argon2id without forcing resets?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.