You never store the password, you store a fingerprint of it. What hashing actually does, why a salt makes every fingerprint unique, why bcrypt and Argon2 are slow on purpose, and the two PHP functions that handle all of it.
Web Development
What is Password Hashing?
One Missing Check: The Password Endpoint That Never Asked Who You Were
SQL Injection (SQLi)
3 posts
All topics ›I went to look at the password change endpoint on my own site and realized it never confirmed the requester actually owned the account. No crash, no error — just quiet, full account takeover. A walkthrough of a textbook Broken Access Control bug and the checks that fix it.
A friendly, plain-English guide to one of the oldest and still pretty dangerous bugs in web security.
No posts in this topic match your search.