Short answer
Never store passwords in plain text or with fast hashes such as SHA-256 alone. Use a slow, salted password hashing function designed for the purpose — Argon2id, scrypt or bcrypt — with a unique salt per password and a work factor tuned to your hardware. Compare hashes in constant time and rehash when you raise the cost.
Why slow hashes
Attackers who steal a database can try billions of fast hashes per second on GPUs. Memory-hard, deliberately slow functions make each guess expensive, and unique salts prevent precomputed tables from working.
Beyond hashing
- Rate-limit login attempts.
- Support multi-factor authentication or passkeys.
- Check new passwords against known breached lists.
How to answer it in an interview
- Explain the difference between hashing and encryption.
- Mention a pepper stored outside the database as an optional extra.