Security & Auth interview question

How should passwords be stored?

Short answer

Never store passwords in plain text or with fast hashes such as SHA-256 alone. Use a slow, salted password hashing function designed for the purpose — Argon2id, scrypt or bcrypt — with a unique salt per password and a work factor tuned to your hardware. Compare hashes in constant time and rehash when you raise the cost.

Why slow hashes

Attackers who steal a database can try billions of fast hashes per second on GPUs. Memory-hard, deliberately slow functions make each guess expensive, and unique salts prevent precomputed tables from working.

Beyond hashing

  • Rate-limit login attempts.
  • Support multi-factor authentication or passkeys.
  • Check new passwords against known breached lists.

How to answer it in an interview

  • Explain the difference between hashing and encryption.
  • Mention a pepper stored outside the database as an optional extra.

Walk into your next interview prepared

Start free, install the Windows app and run a practice session today.