<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Password Hashing on Rietta Cybersecurity</title>
    <link>https://rietta.com/glossary/password-hashing/</link>
    <description>Recent content in Password Hashing on Rietta Cybersecurity</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <copyright>1999-2026 Rietta Inc. All Rights Reserved.</copyright>
    <lastBuildDate>Fri, 02 Oct 2026 08:57:59 -0400</lastBuildDate>
    <atom:link href="https://rietta.com/glossary/password-hashing/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Bad Password Practices are Responsible For Most Data Breaches. You Can do Better.</title>
      <link>https://rietta.com/blog/bad-password-practices-are-responsible-for-most-data-breaches-you-can-do-better/</link>
      <pubDate>Tue, 10 May 2016 11:07:58 -0400</pubDate>
      <guid>https://rietta.com/blog/bad-password-practices-are-responsible-for-most-data-breaches-you-can-do-better/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;http://www.verizonenterprise.com/verizon-insights-lab/dbir/&#34;&gt;2016 Verizon DBIR report&lt;/a&gt; is out and is available for download. Among the findings is the prevalence of data breaches that are attributable to stolen authorization credentials.&lt;/p&gt;&#xA;&lt;p&gt;According to the report &amp;ldquo;63% of confirmed data breaches involved weak, default or stolen passwords&amp;rdquo; (page 20). This is an increase from 2015, when the stat was that 51% of web application breaches were attributable to stolen credentials. If anything is clear, it&amp;rsquo;s that the lowly credential theft is a clear and present danger in information security. It is responsible for more incidents than all the other exotic, technically interesting attacks combined.&lt;/p&gt;</description>
    </item>
    <item>
      <title>What is the difference between bcrypt and SHA256?</title>
      <link>https://rietta.com/blog/bcrypt-not-sha-for-passwords/</link>
      <pubDate>Fri, 05 Feb 2016 10:23:27 -0500</pubDate>
      <guid>https://rietta.com/blog/bcrypt-not-sha-for-passwords/</guid>
      <description>&lt;p&gt;TL;DR; SHA1, SHA256, and SHA512 are all &lt;em&gt;fast hashes&lt;/em&gt; and are bad for passwords. SCRYPT and BCRYPT are both a &lt;em&gt;slow hash&lt;/em&gt; and are good for passwords. Always use slow hashes, never fast hashes.&lt;/p&gt;&#xA;&lt;p&gt;SANS&amp;rsquo; &lt;a href=&#34;https://software-security.sans.org/resources/swat&#34;&gt;Securing Web Application Technologies&#xA;[SWAT] Checklist&lt;/a&gt; is offering a bit of bad security advice for the everyday web application developer, under the heading &amp;ldquo;Store User Passwords Using A Strong, Iterative, Salted Hash&amp;rdquo;:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;User passwords must be stored using secure hashing techniques with a strong algorithm like SHA-256. Simply hashing the password a single time does not sufficiently protect the password. Use iterative hashing with a random salt to make the hash strong.&lt;/p&gt;&#xA;&lt;/blockquote&gt;</description>
    </item>
    <item>
      <title>Really Bad Passwords (with Unsalted Hashes)</title>
      <link>https://rietta.com/blog/really-bad-passwords-with-unsalted-hashes/</link>
      <pubDate>Fri, 08 Jun 2012 18:30:00 +0000</pubDate>
      <guid>https://rietta.com/blog/really-bad-passwords-with-unsalted-hashes/</guid>
      <description>The June, 2012, LinkedIn password breach reminds us all the need to protect our user&amp;rsquo;s passwords.&#xA;The following table includes a series of really, really bad passwords. These are passwords that are trivially cracked using an automated tool, such as John the Ripper, or have been found through public password hacks as being in use by real people. This is a simple rainbow table because it lists the precomputed unsalted SHA1 and MD5 hashes.</description>
    </item>
    <item>
      <title>Web Application Security &amp; Performance</title>
      <link>https://rietta.com/blog/web-application-security-and-performance/</link>
      <pubDate>Tue, 22 Sep 2009 17:07:00 -0500</pubDate>
      <guid>https://rietta.com/blog/web-application-security-and-performance/</guid>
      <description>As a business owner or manager, you need to be aware of the main legal liability and technical challenges that face any critical website or application. Your business will be better positioned to succeed if you understand how to answer these five key questions:&#xA;Is your business making one or more of the top five web application mistakes that generate business risk? How can performance and security assessments help increase your ROI?</description>
    </item>
  </channel>
</rss>
