Storing passwords safely · Armazenando senhas com segurança
The big rule: never store plain passwords
- If a website stores your password as plain text and gets hacked, every password is stolen instantly.
- Instead, sites store a hash — a scrambled fingerprint that cannot be reversed back into the password.
A grande regra: nunca armazene senhas em texto claro
- Se um site armazenar sua senha em texto claro e for hackeado, todas as senhas são roubadas instantaneamente.
- Em vez disso, os sites armazenam um hash — uma impressão digital embaralhada que não pode ser revertida para a senha original.
What is a hash?
- A hash function turns any input into a fixed-length string. The same input always gives the same hash.
- It is one-way: easy to compute forwards, practically impossible to reverse.
- When you log in, the site hashes what you typed and compares it to the stored hash — it only ever stores the hash, never your actual password.
O que é um hash?
- Uma função de hash converte qualquer entrada em uma string de comprimento fixo. A mesma entrada sempre gera o mesmo hash.
- É one-way (um sentido): fácil de calcular no sentido direto, praticamente impossível de reverter.
- Ao fazer login, o site faz o hash do que você digitou e compara com o hash armazenado — ele só armazena o hash, nunca sua senha real.
import hashlib
print(hashlib.sha256(b"hello").hexdigest())
Add salt
- If two users pick the same password, their hashes match — a clue for attackers.
- A salt is a random string added before hashing, so identical passwords get different hashes.
- It also defeats pre-computed "rainbow table" attacks. Always salt.
Adicione sal
- Se dois usuários escolherem a mesma senha, seus hashes correspondem — uma pista para atacantes.
- Um sal é uma string aleatória adicionada antes do hash, então senhas idênticas geram hashes diferentes.
- Isso também derrota ataques de tabelas arco-íris pré-computadas. Sempre use sal.
Your turn
- Hash
salt + passwordwith SHA-256. The check confirms you produced the correct 64-character digest.
Covers: A-Level 6.1, 17.1 (encryption/hashing).
Sua vez
- Hash
salt + passwordcom SHA-256. A verificação confirma que você produziu o digest correto de 64 caracteres.
Cobertura: A-Level 6.1, 17.1 (criptografia/hash).
Common mistakes
- Never store passwords in plain text.
- Store a salted hash, not the password itself.
Erros comuns
- Nunca armazene senhas em texto claro.
- Armazene um hash com sal, não a senha em si.
Store the hash, not the password · Armazene o hash, não a senha
Sites store a hash; a tiny change gives a totally different digest. · Sites armazenam um hash; uma pequena mudança gera um digest totalmente diferente.
Never store a plain password — store its hash. Using hashlib, hash the salt + password with SHA-256 and put the hex digest in a variable called digest. · Nunca armazene uma senha em texto claro — armazene seu hash. Usando hashlib, faça o hash de salt + senha com SHA-256 e coloque o digest hex em uma variável chamada digest.
Click Run to see the output here. · Clique em Executar para ver a saída aqui.
Now be the login system. The database holds a salt and a stored digest — never the password. Hash salt + attempt with SHA-256 and print welcome if it matches stored, else denied. · Agora seja o sistema de login. O banco de dados armazena um salt e um digesto stored — nunca a senha. Calcule o hash de salt + attempt com SHA-256 e imprima welcome se corresponder a stored, caso contrário, imprima denied.
Click Run to see the output here. · Clique em Executar para ver a saída aqui.