This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Password Storage Cheat Sheet
From OWASP
ACTIVE WORK IN PROGRESS AUGUST 2011
Introduction
This article is focused on providing guidance to storing a passwords in order to help prevent password theft.
Password Storage Rules
- Use a Modern Hash
- SHA
- bcrypt
- Use a long cryptograpgically random salt
- Isolate the salt from the hash
- Iterate the hash
OWASP Cheat Sheets Project Homepage