{"id":33099,"date":"2026-08-13T10:53:22","date_gmt":"2026-08-13T10:53:22","guid":{"rendered":"https:\/\/www.bitnovo.com\/blog\/?p=33099"},"modified":"2026-08-13T10:53:22","modified_gmt":"2026-08-13T10:53:22","slug":"how-the-hash-that-protects-your-passwords-on-any-website-works","status":"publish","type":"post","link":"https:\/\/www.bitnovo.com\/blog\/en\/how-the-hash-that-protects-your-passwords-on-any-website-works","title":{"rendered":"How the Hash That Protects Your Passwords on Any Website Works"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_82_2 counter-hierarchy ez-toc-counter ez-toc-transparent ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Alternar tabla de contenidos\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #ffffff;color:#ffffff\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #ffffff;color:#ffffff\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 eztoc-toggle-hide-by-default' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.bitnovo.com\/blog\/en\/how-the-hash-that-protects-your-passwords-on-any-website-works\/#what_a_website_actually_stores_when_you_register\" >What a Website Actually Stores When You Register<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.bitnovo.com\/blog\/en\/how-the-hash-that-protects-your-passwords-on-any-website-works\/#how_a_password_is_converted_into_a_hash\" >How a Password Is Converted into a Hash<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.bitnovo.com\/blog\/en\/how-the-hash-that-protects-your-passwords-on-any-website-works\/#hash_encryption_and_encoding_whats_the_difference\" >Hash, Encryption, and Encoding: What&#8217;s the Difference<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.bitnovo.com\/blog\/en\/how-the-hash-that-protects-your-passwords-on-any-website-works\/#what_an_attacker_finds_in_a_credential_leak\" >What an Attacker Finds in a Credential Leak<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/www.bitnovo.com\/blog\/en\/how-the-hash-that-protects-your-passwords-on-any-website-works\/#why_reusing_passwords_breaks_the_protection_of_hashing\" >Why Reusing Passwords Breaks the Protection of Hashing<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/www.bitnovo.com\/blog\/en\/how-the-hash-that-protects-your-passwords-on-any-website-works\/#salt_and_modern_algorithms_how_the_system_has_been_strengthened\" >Salt and Modern Algorithms: How the System Has Been Strengthened<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/www.bitnovo.com\/blog\/en\/how-the-hash-that-protects-your-passwords-on-any-website-works\/#faq\" >FAQ<\/a><\/li><\/ul><\/nav><\/div>\n<span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">Tiempo de lectura:<\/span> <span class=\"rt-time\"> 7<\/span> <span class=\"rt-label rt-postfix\">minutos<\/span><\/span><p>Imagine waking up one day, turning on the news, and discovering that someone has left the front door of half the Internet wide open. That was exactly what happened when a team of researchers from Cybernews <a href=\"https:\/\/cybernews.com\/security\/billions-credentials-exposed-infostealers-data-leak\/\">uncovered<\/a> a monumental leak: more than\u00a0<strong>16 billion credentials<\/strong>\u00a0exposed on the network.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter wp-image-33100 size-full\" src=\"https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/1-11.jpg\" alt=\"\" width=\"1023\" height=\"573\" srcset=\"https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/1-11.jpg 1023w, https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/1-11-300x168.jpg 300w, https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/1-11-768x430.jpg 768w\" sizes=\"(max-width: 1023px) 100vw, 1023px\" \/><\/p>\n<p>Usernames and passwords linked to services like Google, Meta, GitHub, Apple, and even government portals were exposed. Most of this data came from\u00a0<strong>infostealers<\/strong>, malicious programs filtered from users&#8217; devices, organized into 30 large data batches accessible on vulnerable servers. The experts themselves were quick to describe the event not just as a massive leak but as a true\u00a0<strong>\u00abmass exploitation project.\u00bb<\/strong>\u00a0A banquet ready to serve cyber scams, identity theft, and bank account hijackings.<\/p>\n<p>By the way,\u00a0<strong>Volodymir Diachenko<\/strong>, one of the authors of the investigation, clarified in the article itself that there was no data breach centered on any of these tech companies, but the credentials contained login links to those platforms.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-33101 size-full\" src=\"https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/2-11.jpg\" alt=\"\" width=\"1023\" height=\"573\" srcset=\"https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/2-11.jpg 1023w, https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/2-11-300x168.jpg 300w, https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/2-11-768x430.jpg 768w\" sizes=\"(max-width: 1023px) 100vw, 1023px\" \/><\/p>\n<p>Now, faced with such a volume of information circulating on the Internet, the logical question is: Why didn&#8217;t the digital world collapse instantly? Why didn&#8217;t they empty your bank account that same night?<\/p>\n<p>The answer lies in an invisible mathematical piece that has been working in the background for decades without you noticing:\u00a0<strong>the <a href=\"https:\/\/en.wiktionary.org\/wiki\/hash\">hash<\/a>.<\/strong><\/p>\n<p>Throughout this post, you will understand how this essential tool works, why it is the difference between a serious scare and a disaster, and how it ensures that even when cybercriminals manage to open the safe, all they find inside is a bunch of useless hieroglyphics.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"what_a_website_actually_stores_when_you_register\"><\/span><strong>What a Website Actually Stores When You Register<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Precisely to prevent all those stolen credentials from becoming a direct gateway to your private life, digital security begins by breaking a very common myth: the idea that servers store your password exactly as you type it.<\/p>\n<p>Although we often think that our information lives floating in that famous\u00a0<strong>\u00abcloud,\u00bb<\/strong>\u00a0the way access to your accounts is stored is much more clever. The truth is, if any platform stored your plain text in its databases, it would be enough for an attacker to\u00a0<strong>\u00abfish\u00bb<\/strong>\u00a0that information to have the master key to your account.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-33102 size-large\" src=\"https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/3-16-1024x768.jpg\" alt=\"\" width=\"1024\" height=\"768\" srcset=\"https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/3-16-1024x768.jpg 1024w, https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/3-16-300x225.jpg 300w, https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/3-16-768x576.jpg 768w, https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/3-16.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>That is precisely why no website with a minimum of security ever stores your real password. Instead, the platform only stores a derived result:\u00a0<strong>the <a href=\"https:\/\/bitwarden.com\/resources\/what-is-password-hashing\/\">hash<\/a>.<\/strong>\u00a0You can imagine it as a kind of unique digital fingerprint or a mathematical receipt. Just as a fingerprint identifies a person without needing to clone it entirely, the hash identifies your password without needing to store it on the server. If someone manages to access that database, they won&#8217;t find your key, but a series of characters that, at first glance, mean nothing.<\/p>\n<p>But this leads us to the great riddle of the system: if the website doesn&#8217;t know your password and doesn&#8217;t have it stored on its servers, how does it know it&#8217;s you when you try to log in?<\/p>\n<h2><span class=\"ez-toc-section\" id=\"how_a_password_is_converted_into_a_hash\"><\/span><strong>How a Password Is Converted into a Hash<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>To understand how the website confirms your identity, we need to look closely at cryptography. The answer is as simple as it is ingenious: the platform doesn&#8217;t need to remember your key; it only needs to repeat the same mathematical recipe every time you return. The process follows a direct and transparent flow:<\/p>\n<ol>\n<li><strong>You type your password:<\/strong>You enter your key when registering.<\/li>\n<li><strong>The mathematical machine kicks in:<\/strong>The website takes that plain text and passes it through a hash function.<\/li>\n<li><strong>The hash is generated:<\/strong>The function processes that data and returns a fixed-length alphanumeric string (something like e3b0t484298fc1c149afbf4y83996fb92427ac41e4649b9534co4995991p7852b855). That string is exactly the only thing stored in the server&#8217;s database.<\/li>\n<\/ol>\n<p>When you return minutes later and try to log in, the website does not look for or recover your original key. It simply takes what you just typed in the box, applies the same mathematical function again, and compares the two <a href=\"https:\/\/www.bitnovo.com\/blog\/en\/hash-blockchain-detect-real-content\">hashes<\/a>. If both strings match character by character, the system confirms that you entered the correct key and grants you immediate access.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-28200 size-full\" src=\"https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2025\/12\/1.jpg\" alt=\"\" width=\"768\" height=\"526\" srcset=\"https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2025\/12\/1.jpg 768w, https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2025\/12\/1-300x205.jpg 300w\" sizes=\"(max-width: 768px) 100vw, 768px\" \/><\/p>\n<p>This entire mechanism sustains its security on two golden rules:<\/p>\n<ul>\n<li><strong>Irreversibility (one-way):<\/strong>The hash of any password can be calculated in a millisecond, but it is impossible to reverse the process to decipher the original text from the <a href=\"https:\/\/www.bitnovo.com\/blog\/en\/what-is-a-hash-definition-function-and-security\">hash<\/a>.<\/li>\n<li><strong>Determinism and uniqueness (same key = same hash):<\/strong>If you enter the same key a thousand times, you will get exactly the same hash every time. But changing just one character, an uppercase letter, or a sign will make the final result completely different and unpredictable.<\/li>\n<\/ul>\n<p>Thanks to these two properties, hashing adds a giant wall of complexity: even if an attacker manages to access the database, they cannot read your keys or use them directly.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"hash_encryption_and_encoding_whats_the_difference\"><\/span><strong>Hash, Encryption, and Encoding: What&#8217;s the Difference<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>To fully understand why hashing is the undisputed king when protecting credentials, it is worth pausing. In the software world, it is very common to hear the phrase\u00a0<strong>\u00abI saved the key encrypted in Base64.\u00bb<\/strong>\u00a0If you have ever said or thought this, don&#8217;t worry, but it&#8217;s time to clarify that encoding, encryption, and hashing are not the same, and confusing them in production can be a disaster.<\/p>\n<p>Although all three processes transform readable text into an unrecognizable string, their objectives are completely different:<\/p>\n<ul>\n<li><strong>Encoding (Base64):<\/strong>It only changes the format. Its sole purpose is compatibility between systems. It does not use keys or offer any protection: anyone can take a Base64 string and press\u00a0<strong>\u00abdecode\u00bb<\/strong>\u00a0to see the original content in seconds.<\/li>\n<li><strong>Encryption:<\/strong>Confidentiality in two directions. Encryption transforms data so that no one can read it, but it requires a key to unlock it. It is perfect for sending a private message on WhatsApp or browsing via HTTPS, but disastrous for storing passwords.<\/li>\n<li><strong>Hash:<\/strong>A single direction. The hash creates a fixed-length cryptographic summary in one direction. There is no key to\u00a0<strong>\u00abunlock\u00bb<\/strong>\u00a0it because mathematically there is no way back.<\/li>\n<\/ul>\n<table style=\"height: 115px;\" width=\"1133\">\n<thead>\n<tr>\n<td>\n<p style=\"text-align: center;\"><strong>Property<\/strong><\/p>\n<\/td>\n<td style=\"text-align: center;\"><strong>Encoding<\/strong><\/td>\n<td style=\"text-align: center;\"><strong>Encryption<\/strong><\/td>\n<td>\n<p style=\"text-align: center;\"><strong>Hash<\/strong><\/p>\n<\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Purpose<\/strong><\/td>\n<td>Compatibility and format<\/td>\n<td>Reversible confidentiality<\/td>\n<td><strong>Integrity and passwords<\/strong><\/td>\n<\/tr>\n<tr>\n<td><strong>Is it reversible?<\/strong><\/td>\n<td>Yes (anyone can do it)<\/td>\n<td>Yes (only with the correct key)<\/td>\n<td><strong>No (one-way)<\/strong><\/td>\n<\/tr>\n<tr>\n<td><strong>Does it require a key?<\/strong><\/td>\n<td>No<\/td>\n<td>Yes<\/td>\n<td>No<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2><span class=\"ez-toc-section\" id=\"what_an_attacker_finds_in_a_credential_leak\"><\/span><strong>What an Attacker Finds in a Credential Leak<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>With the barrier that hashing provides now clear, let&#8217;s return for a moment to the mega leak of June 2025 we discussed at the beginning. When cybercriminals manage to penetrate a server&#8217;s security or download an exposed database, what exactly do they see on their screens?<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-33103 size-full\" src=\"https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/5-16.jpg\" alt=\"\" width=\"1024\" height=\"682\" srcset=\"https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/5-16.jpg 1024w, https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/5-16-300x200.jpg 300w, https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/5-16-768x512.jpg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>On a well-built platform, the loot from a leak looks like a cold and incomprehensible table:<\/p>\n<table style=\"height: 93px;\" width=\"1113\">\n<thead>\n<tr>\n<td>\n<p style=\"text-align: center;\"><strong>User<\/strong><\/p>\n<\/td>\n<td>\n<p style=\"text-align: center;\"><strong>Hash stored on the server<\/strong><\/p>\n<\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>usuario_1@gmail.com<\/td>\n<td>5e884898da28047151d0e56f8dc6292773603d0d6aabbdd62a11ef721d1542d8<\/td>\n<\/tr>\n<tr>\n<td>usuario_2@outlook.com<\/td>\n<td>e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>At first glance, this list is cryptographically useless for a direct attack. If the attacker tries to go to the website&#8217;s login screen and types\u00a0<strong>5e884898da28&#8230;<\/strong>\u00a0in the password box, the system will reject access immediately, because it will process that string again and generate a completely different hash.<\/p>\n<p>The problem is that the risk does not end there. The real trouble begins when attackers seek to turn those data packets into functional credentials to launch massive\u00a0<strong>credential stuffing<\/strong>\u00a0campaigns. Using bots and automated tools, they test millions of combinations in minutes against thousands of websites, banks, and online services simultaneously.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-33104 size-full\" src=\"https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/6-11.jpg\" alt=\"\" width=\"612\" height=\"408\" srcset=\"https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/6-11.jpg 612w, https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/6-11-300x200.jpg 300w\" sizes=\"(max-width: 612px) 100vw, 612px\" \/><\/p>\n<p>However, for a bot to try its luck at your bank or email, the attacker needs to take a previous step: figure out which original password generated that character string. And that is precisely where the human factor and the most common mistake of all come into play.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"why_reusing_passwords_breaks_the_protection_of_hashing\"><\/span><strong>Why Reusing Passwords Breaks the Protection of Hashing<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>That is where the hash&#8217;s shield cracks, not because of the mathematics but because of our habits. Being a deterministic system, if the key is predictable, the hash is too.<\/p>\n<p>Attackers exploit this using\u00a0<strong>rainbow tables<\/strong>: massive lists with millions of common keys (like\u00a0<strong>123456<\/strong>\u00a0or\u00a0<strong>password<\/strong>) and their already calculated hashes. When they steal a database, they don&#8217;t crack the hash; they just look it up in their table and, in seconds, obtain the plain-text key.<\/p>\n<p>If you reuse that same password on your email, your bank, and your social networks, the disaster multiplies. Bots only need one single website to suffer a leak to obtain your key and suddenly open the door to all your accounts. Hashing protects you from the volume, but not from bad digital hygiene.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"salt_and_modern_algorithms_how_the_system_has_been_strengthened\"><\/span><strong>Salt and Modern Algorithms: How the System Has Been Strengthened<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>To combat rainbow tables and the accelerated advancement of hardware used by attackers, the industry has evolved with two fundamental improvements that reinforce the original protection of hashing:<\/p>\n<table style=\"height: 121px;\" width=\"1133\">\n<thead>\n<tr>\n<td>\n<p style=\"text-align: center;\"><strong>Technical Improvement<\/strong><\/p>\n<\/td>\n<td style=\"text-align: center;\"><strong>What does it consist of?<\/strong><\/td>\n<td>\n<p style=\"text-align: center;\"><strong>Impact on security<\/strong><\/p>\n<\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Salt<\/strong><\/td>\n<td>Adds a unique, random string of text to each password before processing the hash.<\/td>\n<td><strong>Invalidates rainbow tables.<\/strong>\u00a0Two people with the same key (e.g., 123456) will have completely different hashes in the database.<\/td>\n<\/tr>\n<tr>\n<td><strong>Slow and intensive algorithms (bcrypt, scrypt, Argon2)<\/strong><\/td>\n<td>Algorithms intentionally designed to consume a lot of time and RAM when calculating the hash.<\/td>\n<td><strong>Slow down large-scale brute-force attacks,<\/strong>\u00a0making it unfeasible to test millions of combinations per second with GPUs or graphics cards.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>That June 2025 disaster, with\u00a0<strong>16 billion records exposed<\/strong>\u00a0on the network, did not end in an absolute digital collapse precisely because of this mechanism. Behind every login to Google, Meta, or your online banking, hashing operates as\u00a0<strong>silent infrastructure<\/strong>: a mathematical wall that activates in a millisecond every time you press\u00a0<strong>\u00abEnter\u00bb<\/strong>\u00a0to protect your identity without you noticing.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-33105 size-full\" src=\"https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/7-1.jpg\" alt=\"\" width=\"612\" height=\"459\" srcset=\"https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/7-1.jpg 612w, https:\/\/www.bitnovo.com\/blog\/wp-content\/uploads\/2026\/08\/7-1-300x225.jpg 300w\" sizes=\"(max-width: 612px) 100vw, 612px\" \/><\/p>\n<p>However, even the most sophisticated algorithm in the world cannot replace digital hygiene. The cryptographic architecture does its part of the heavy lifting against massive leaks; it&#8217;s up to us to do the other half:\u00a0<strong>use <a href=\"https:\/\/www.bitnovo.com\/blog\/en\/what-is-the-security-seed\">long<\/a>, complex, and strictly unique passwords for each service.<\/strong><\/p>\n<h2><span class=\"ez-toc-section\" id=\"faq\"><\/span><strong>FAQ<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ul>\n<li><strong>Why don&#8217;t websites store my real password?<\/strong>To protect your security. Websites store a hash derived from your key; thus, if they suffer a cyberattack, attackers do not obtain your password in plain text.<\/li>\n<li><strong>What exactly is a cryptographic hash?<\/strong>It is a fixed-length alphanumeric string generated by a one-way mathematical function. It allows verifying that your password is correct without needing to know or store it.<\/li>\n<li><strong>How is hashing different from traditional encryption?<\/strong>Encryption is two-way, while hashing is strictly one-way.<\/li>\n<li><strong>What is \u00absalt\u00bb in password security?<\/strong>It is a random text that the website adds to your key before generating the hash. This prevents two identical passwords from having the same hash and renders precomputed table attacks useless.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p><span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">Tiempo de lectura:<\/span> <span class=\"rt-time\"> 7<\/span> <span class=\"rt-label rt-postfix\">minutos<\/span><\/span>In 2025, 16 billion credentials were leaked. Hashing is the technical piece that prevented every password from being exposed in plain text.<\/p>\n","protected":false},"author":12,"featured_media":33091,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[185],"tags":[],"class_list":["post-33099","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain-en"],"_links":{"self":[{"href":"https:\/\/www.bitnovo.com\/blog\/wp-json\/wp\/v2\/posts\/33099","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bitnovo.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bitnovo.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bitnovo.com\/blog\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bitnovo.com\/blog\/wp-json\/wp\/v2\/comments?post=33099"}],"version-history":[{"count":3,"href":"https:\/\/www.bitnovo.com\/blog\/wp-json\/wp\/v2\/posts\/33099\/revisions"}],"predecessor-version":[{"id":33303,"href":"https:\/\/www.bitnovo.com\/blog\/wp-json\/wp\/v2\/posts\/33099\/revisions\/33303"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.bitnovo.com\/blog\/wp-json\/wp\/v2\/media\/33091"}],"wp:attachment":[{"href":"https:\/\/www.bitnovo.com\/blog\/wp-json\/wp\/v2\/media?parent=33099"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bitnovo.com\/blog\/wp-json\/wp\/v2\/categories?post=33099"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bitnovo.com\/blog\/wp-json\/wp\/v2\/tags?post=33099"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}