About this interactive
Storing password hashes instead of passwords is the first defense, but the lesson starts from the moment that defense is tested: the table has been stolen. This activity runs that scenario again and again with different defenses in place, and asks you to predict what the attacker gets.
A plain hash cannot be reversed, but it can be looked up. A rainbow table is a precomputed list of passwords and their hashes, so a common password is found in an instant. Long passwords are far less likely to be in one.
A salt is a random value added to each user's password before it is hashed. It makes the stored hashes unlike anything in a precomputed table, so rainbow tables stop working. Because each user has their own salt and the system needs it at every login, it is stored in the same table, so a stolen table hands the attacker the salts too. They can still guess: add the salt to each guess, hash it, and compare.
A pepper is a secret value added the same way, but stored somewhere else: in the application code or in hardware. If only the database is stolen, the attacker is missing a piece of every hash and their guesses never match. A separate pepper for every user is costly to look up, so systems often use one pepper for everyone, and if that single value leaks, it protects nobody. Neither salt nor pepper stops an insider who can read both locations.
Key stretching runs the hashing process many times, for example a thousand. Every guess the attacker makes now costs a thousand hashes, so guessing slows down a thousandfold. The server pays the same cost at every login, so the setting has to be high enough to hurt attackers and low enough not to hurt users.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →