Storing passwords safely
This page needs a recent browser (with SharedArrayBuffer support). Please update Chrome, Edge, Firefox or Safari to the latest version. · このページには最新のブラウザ(SharedArrayBuffer対応)が必要です。Chrome、Edge、Firefox、Safariを最新バージョンに更新してください。
English
The big rule: never store plain passwords
- If a website stores your password as plain text and gets hacked, every password is stolen instantly.
- Instead, sites store a hash — a scrambled fingerprint that cannot be reversed back into the password.
日本語
最重要ルール:平文でのパスワード保存は絶対に行わない
- ウェブサイトがあなたのパスワードを平文で保存し、ハッキングされた場合、すべてのパスワードが瞬時に盗まれます。
- 代わりに、サイトはハッシュを保存します。これは復元不可能な、かき混ぜられた指紋のようなものです。
English
What is a hash?
- A hash function turns any input into a fixed-length string. The same input always gives the same hash.
- It is one-way: easy to compute forwards, practically impossible to reverse.
- When you log in, the site hashes what you typed and compares it to the stored hash — it only ever stores the hash, never your actual password.
日本語
ハッシュとは何か
- ハッシュ関数は、あらゆる入力を固定長の文字列に変換します。同じ入力には常に同じハッシュが生成されます。
- それは一方向性です:前方への計算は容易ですが、逆算することは実質的に不可能です。
- ログイン時、サイトは入力した内容のハッシュを生成し、保存されたハッシュと比較します。サイトが実際に保存するのはハッシュのみであり、あなたの実際のパスワードではありません。
import hashlib
print(hashlib.sha256(b"hello").hexdigest())
English
Add salt
- If two users pick the same password, their hashes match — a clue for attackers.
- A salt is a random string added before hashing, so identical passwords get different hashes.
- It also defeats pre-computed "rainbow table" attacks. Always salt.
日本語
ソルトを追加する
- 2人のユーザーが同じパスワードを選んだ場合、そのハッシュも一致してしまい、攻撃者にとって手がかりとなります。
- ソルトとは、ハッシュ処理の前に追加されるランダムな文字列であり、同じパスワードでも異なるハッシュを生み出します。
- また、事前計算済み「レインボーテーブル」攻撃を防ぐ効果もあります。必ずソルトを使用してください。
English
Your turn
- Hash
salt + passwordwith SHA-256. The check confirms you produced the correct 64-character digest.
Covers: A-Level 6.1, 17.1 (encryption/hashing).
日本語
実践
salt + passwordをSHA-256でハッシュ化してください。チェックにより、正しい64文字のダイジェストが生成されたことが確認できます。
対象: A-Level 6.1, 17.1 (暗号化/ハッシュ).
English
Common mistakes
- Never store passwords in plain text.
- Store a salted hash, not the password itself.
日本語
よくあるミス
- 平文でパスワードを保存してはならない。
- パスワードそのものではなく、ソルト付きのハッシュを保存する。
Explore · 探索
Store the hash, not the password
Sites store a hash; a tiny change gives a totally different digest.
Never store a plain password — store its hash. Using hashlib, hash the salt + password with SHA-256 and put the hex digest in a variable called digest.
Click Run to see the output here. · 実行ボタンをクリックして出力を確認してください。
Now be the login system. The database holds a salt and a stored digest — never the password. Hash salt + attempt with SHA-256 and print welcome if it matches stored, else denied.
Click Run to see the output here. · 実行ボタンをクリックして出力を確認してください。