Storing passwords safely · เก็บรหัสผ่านอย่างปลอดภัย
The big rule: never store plain passwords
- If a website stores your password as plain text and gets hacked, every password is stolen instantly.
- Instead, sites store a hash — a scrambled fingerprint that cannot be reversed back into the password.
กฎสำคัญ: ห้ามเก็บรหัสผ่านแบบข้อความธรรมดา
- หากเว็บไซต์เก็บรหัสผ่านของคุณในรูปแบบข้อความธรรมดาและถูกแฮก รหัสผ่านทั้งหมดจะถูกขโมยทันที
- แทนที่จะทำเช่นนั้น เว็บไซต์จะเก็บ แฮช (hash) — ซึ่งเป็นลายนิ้วมือที่สุ่มที่กลับคืนเป็นรหัสผ่านไม่ได้
What is a hash?
- A hash function turns any input into a fixed-length string. The same input always gives the same hash.
- It is one-way: easy to compute forwards, practically impossible to reverse.
- When you log in, the site hashes what you typed and compares it to the stored hash — it only ever stores the hash, never your actual password.
แฮชคืออะไร?
- ฟังก์ชัน แฮช เปลี่ยนอินพุตใดๆ ให้เป็นสายอักขระที่มีความยาวคงที่ อินพุตเดิมจะให้ค่าแฮชเดิมเสมอ
- มันเป็นทาง เดียว: คำนวณไปข้างหน้าได้ง่าย แต่anking back几乎是 impossible
- เมื่อคุณเข้าสู่ระบบ เว็บไซต์จะแฮชสิ่งที่พิมพ์แล้วเปรียบเทียบกับค่าแฮชที่เก็บไว้ — มันจะเก็บแค่ค่าแฮชเท่านั้น ไม่เคยเก็บรหัสผ่านจริงของคุณ
import hashlib
print(hashlib.sha256(b"hello").hexdigest())
Add salt
- If two users pick the same password, their hashes match — a clue for attackers.
- A salt is a random string added before hashing, so identical passwords get different hashes.
- It also defeats pre-computed "rainbow table" attacks. Always salt.
เพิ่มเกลือ
- หากผู้ใช้สองคนเลือกรหัสผ่านเหมือนกัน ค่าแฮชของพวกเขาจะตรงกัน — ซึ่งเป็นจุดอ่อนให้ผู้โจมตีใช้
- เกลือ (salt) คือสายอักขระสุ่มที่เพิ่มเข้าไปก่อนการทำแฮช ทำให้รหัสผ่านเหมือนกันแต่ได้ค่าแฮชต่างกัน
- เกลือยังช่วยต้านการโจมตีด้วย "rainbow table" ที่คำนวณไว้ล่วงหน้า ควรใช้เกลือเสมอ
Your turn
- Hash
salt + passwordwith SHA-256. The check confirms you produced the correct 64-character digest.
Covers: A-Level 6.1, 17.1 (encryption/hashing).
ถึงเวลาฝึกฝน
- แฮช
salt + passwordด้วย SHA-256 ระบบจะตรวจสอบว่าคุณสร้าง digest ที่มีความยาว 64 ตัวอักษรถูกต้องหรือไม่
ครอบคลุม: A-Level 6.1, 17.1 (การเข้ารหัส/แฮช).
Common mistakes
- Never store passwords in plain text.
- Store a salted hash, not the password itself.
ข้อผิดพลาดที่พบบ่อย
- ห้ามเก็บรหัสผ่านในรูปแบบข้อความธรรมดา
- เก็บค่าแฮชที่มีเกลือ ไม่ใช่รหัสผ่านเอง
Store the hash, not the password · เก็บ hash, ไม่ใช่รหัสผ่าน
Sites store a hash; a tiny change gives a totally different digest. · เว็บไซต์เก็บ hash; การเปลี่ยนแปลงเล็กน้อยให้ digest ที่แตกต่างสิ้นเชิง
Never store a plain password — store its hash. Using hashlib, hash the salt + password with SHA-256 and put the hex digest in a variable called digest. · อย่า-ever เก็บรหัสผ่านธรรมดา — เก็บ hash ของมัน. ใช้ hashlib, hash salt + รหัสผ่าน ด้วย SHA-256 และใส่ hex digest ลงในตัวแปรชื่อ digest
Click Run to see the output here. · คลิก Run เพื่อดูผลลัพธ์ที่นี่
Now be the login system. The database holds a salt and a stored digest — never the password. Hash salt + attempt with SHA-256 and print welcome if it matches stored, else denied. · ตอนนี้จงเป็นระบบล็อกอิน. ฐานข้อมูลมี salt และ digest stored — ไม่-ever มีรหัสผ่าน. Hash salt + attempt ด้วย SHA-256 และพิมพ์ welcomeหากตรงกับ stored, มิฉะนั้นพิมพ์ denied
Click Run to see the output here. · คลิก Run เพื่อดูผลลัพธ์ที่นี่