Description
Fast hashes such as SHA-2 and SHA-3 remain unsuitable for password storage even when they resist collisions. Their low computational cost makes offline password guessing inexpensive.
Potential impact
- Lower password-cracking costs
- Increased chance of recovering passwords from leaked hashes
- Account takeover and authentication bypass
Remediation
- Use password-specific algorithms such as Argon2id, bcrypt, scrypt, or PBKDF2.
- Keep general integrity hashing separate from password storage.
- Generate salts with secure randomness, choose work-factor parameters for the environment, and review the policy periodically.
Examples
Before
swift
let passwordHash = SHA512.hash(data: passwordData)
After
swift
let result = try Argon2Swift.hashPasswordString(password: password, salt: salt)
Explanation:
- Before: SHA-512 is a fast general-purpose hash and is unsuitable for password storage.
- After: A password-specific hashing algorithm raises the cost of offline guessing.