Storing passwords safely · אחסון סיסמאות בבטיחות
The big rule: never store plain passwords
- If a website stores your password as plain text and gets hacked, every password is stolen instantly.
- Instead, sites store a hash — a scrambled fingerprint that cannot be reversed back into the password.
הכלל המרכזי: לעולם אל תאחסן סיסמות בטקסט גלוי
- אם אתר מאחסן את הסיסמה שלך כטקסט גלוי ומוחלץ, כל הסיסמות נגנבות מיד.
- במקום זאת, אתרים מאחסנים חשש — טביעת אצבע מעורבלת שאין להפוך אותה חזרה לסיסמה.
What is a hash?
- A hash function turns any input into a fixed-length string. The same input always gives the same hash.
- It is one-way: easy to compute forwards, practically impossible to reverse.
- When you log in, the site hashes what you typed and compares it to the stored hash — it only ever stores the hash, never your actual password.
מהו חשש?
- פונקציית חשש ממרת כל נתון ליצירת מחרוזת בעלת אורך קבוע. אותו נתון תמיד יניב אותו חשש.
- הוא חד-כיווני: קל לחשב בכיוון הקדמי, ולמעשה בלתי אפשרי להפוך לאחור.
- כאשר מתחברים, האתר מחשב את מה שהקלטת ומשווה אותו לחשש המאוחסן — הוא מאחסן רק את החשש, לעולם לא את הסיסמה האמיתית שלך.
import hashlib
print(hashlib.sha256(b"hello").hexdigest())
Add salt
- If two users pick the same password, their hashes match — a clue for attackers.
- A salt is a random string added before hashing, so identical passwords get different hashes.
- It also defeats pre-computed "rainbow table" attacks. Always salt.
הוסף תבנית
- אם שני משתמשים בוחרים את אותה סיסמה, החששים שלהם זהים — נקודה לעומדים.
- מלח הוא מחרוזת אקראית המוסיפה לפני החישוב, כך שסיסמאות זהות מקבלות חישובים שונים.
- היא גם מנטרלת התקפות טבלאות "קשת-גשם" מוכנות מראש. תמיד הוסף מלח.
Your turn
- Hash
salt + passwordwith SHA-256. The check confirms you produced the correct 64-character digest.
Covers: A-Level 6.1, 17.1 (encryption/hashing).
תורך
- חשב
salt + passwordעם SHA-256. הבדיקה מאשרת שהפקת את ההודעה הקריפטוגרפית הנכונה בעלת 64 תווים.
מכסה: A-Level 6.1, 17.1 (הצפנה/חישוב).
Common mistakes
- Never store passwords in plain text.
- Store a salted hash, not the password itself.
טעויות נפוצות
- לעולם אל תאחסן סיסמאות בטקסט גלוי.
- אחסן חישוב עם מלח, ולא את הסיסמה עצמה.
Store the hash, not the password · אחסן את החשף, לא את הסיסמה
Sites store a hash; a tiny change gives a totally different digest. · אתרים מאחסנים חשף; שינוי קטן גורם לתוצאת גיבוי שונה לחלוטין.
Never store a plain password — store its hash. Using hashlib, hash the salt + password with SHA-256 and put the hex digest in a variable called digest. · לעולם אל תאחסן סיסמה בגלל – אחסן את ה-חשף שלה. השתמש בhashlib כדי לחשב חשף של המלח + הסיסמה באמצעות SHA-256 ושים את תוצאת הגיבוי ההקסדצימלית במשתנה בשם digest.
Click Run to see the output here. · לחץ על הרץ כדי לראות את התוצא כאן.
Now be the login system. The database holds a salt and a stored digest — never the password. Hash salt + attempt with SHA-256 and print welcome if it matches stored, else denied. · עכשיו תהיה מערכת הכניסה. המאגר מכיל salt ותוצאת גיבוי stored – לעולם לא את הסיסמה. חשב חשף של salt + attempt באמצעות SHA-256 והדפס welcome אם הוא תואם לstored, אחרת הדפס denied.
Click Run to see the output here. · לחץ על הרץ כדי לראות את התוצא כאן.