🔐
Security

Password hashing: bcrypt, argon2

09.03.2025
← All articles

MD5/SHA-1 obsolete. Today — modern hashing.

Why just hash isn't enough

Rainbow tables, brute force GPU.

bcrypt

Slow — brute force hard. Cost 12-14.

PHP

password_hash($pass, PASSWORD_BCRYPT).

Argon2

PHC winner. PASSWORD_ARGON2ID.

Salt

Automatic.

Pepper

In .env, not DB.

2FA

Always add.

Related articles

🔐 Password managers — choosing between Bitwarden, 1Password, LastPass and KeePass 🍯 Honeypot — hidden form field that catches bots and stops spam 📄 /.well-known/security.txt — security contact standard 📋 GDPR Compliance — obligations for protecting European citizens' data
🌐 Language
🇺🇿 O'zbek 🇺🇿 Ўзбек 🇷🇺 Русский 🇬🇧 English ✓