Why Are Passwords Hashed Instead of Encrypted?

Why Are Passwords Hashed Instead of Encrypted?

A complete, beginner-to-production walkthrough of why every well-built login system stores password hashes instead of encrypted passwords: the 1962 MIT CTSS printer incident, Robert Morris Sr.’s 1970s Unix crypt-with-salt scheme, and the timeline through bcrypt (1999), PBKDF2 (2000), scrypt (2009), and Argon2id’s 2015 Password Hashing Competition win; the core motivation…

Read More
What Is Cross-Site Request Forgery?

What Is Cross-Site Request Forgery (CSRF)?

A complete, beginner-to-production guide to Cross-Site Request Forgery (CSRF): the bank-tab origin story, Peter Watkins coining the term around 2001, and the timeline from Netscape’s 1994 cookie introduction through the 2006-2007 Netflix, YouTube, and Gmail disclosures to today’s SameSite-by-default browsers; the confused-deputy problem separating authentication from intent; ten core concepts…

Read More