Password Hashing Interview Questions: Common Mistakes to Avoid

Learn effective password hashing strategies to ensure secure user authentication in your systems, avoiding pitfalls during interviews and production.

In a world increasingly threatened by cyberattacks, understanding how to securely store passwords is a fundamental skill for developers. When tasked with password storage, many candidates instinctively rush to implement a basic hashing function without adequate consideration for security nuances. This lack of diligence can lead to catastrophic security failures and, worse, can be a deal-breaker in technical interviews.

The Practice of Password Hashing

Password hashing is not just about converting a password into a “hidden” format—it’s about balancing security, performance, and user experience. The core principle is that even if the hashed passwords are exposed, they should not be easily reversible, minimizing the risk of unauthorized access. When implementing password hashing, you typically have two choices:

  1. Fast hashing algorithms (e.g., MD5, SHA-1): These algorithms are quick, making login processes smooth. However, they are insufficient against modern brute-force attacks due to their speed.

  2. Adaptive hashing algorithms (e.g., bcrypt, Argon2): These are deliberately slow, which adds a barrier to brute-force attacks because they take longer to compute, making it costlier in terms of time and resources for attackers.

Here’s an example of how you might use bcrypt to hash a password in a Node.js application:

const bcrypt = require('bcrypt');
const saltRounds = 10;

async function hashPassword(plainPassword) {
    const hash = await bcrypt.hash(plainPassword, saltRounds);
    return hash;
}

async function comparePassword(plainPassword, hash) {
    const match = await bcrypt.compare(plainPassword, hash);
    return match;
}

In the example above, the saltRounds parameter determines how much time hashing will take. Using a higher value leads to great security at the cost of performance.

Common Interview Traps

When candidates encounter hashing-related questions in interviews, they often overlook specific aspects that interviewers are keen to explore:

  • Overreliance on Fast Algorithms: Candidates might advocate for using fast hashing algorithms for their speed without acknowledging the trade-off in security. Interviewers may want to explore how well you understand the implications of using such algorithms and their vulnerability to attacks.

  • Misunderstanding Salt and Hash: Some candidates may confuse the purpose of salting with simply hashing. Salting is crucial for protecting against rainbow table attacks, and failure to mention this shows a lack of depth in understanding hashing security.

  • Neglecting Rate Limiting: Candidates might propose a strong hashing function but fail to discuss additional measures like rate limiting. This oversight can indicate a limitation in their understanding of holistic security practices.

  • Failure to Test Password Strength: Interviewers often look for candidates who understand that simply hashing a weak password (like "123456") is not secure. They may probe how you would encourage strong password practices in users.

Reasoning Through a Worked Example

Consider a scenario where your application currently uses a fast hashing algorithm such as MD5, which provides minimal security against brute-force attacks. You are tasked with redesigning this system:

  1. Option 1: Keep the fast algorithm but implement rate limiting on login attempts.
  2. Option 2: Switch to a slow hashing algorithm like bcrypt.

Let’s evaluate these options:

  • Rate Limiting can mitigate some brute-force attack risks but ultimately doesn’t stop an attacker from using the speed of MD5 to their advantage. It merely slows them down.
  • Switching to bcrypt effectively hardens the password storage without compromising user experience severely. With a configurable saltRounds, you can balance performance and security.

In this case, recommending the slow hashing approach (bcrypt) would be advisable, as it provides substantial security improvements against both brute-force and other attacks, signaling to the interviewer that you grasp the importance of robust password security implementations.

Real-World Considerations

In production, password hashing is where developers often find themselves grappling with real-world scenarios:

  • User Experience vs. Security: While bcrypt enhances security, it may also increase login times. Developers must find the right balance and possibly inform users about the reasoning behind slightly longer authentication times.

  • Database and Storage Requirements: Hashed passwords stored in databases require extra consideration for size—adaptive hashing algorithms often produce longer hashes, which necessitates appropriate column sizes in databases.

  • Migration Challenges: When switching from a fast hashing algorithm to a secure one, you need a migration strategy. Old passwords must remain verifiable until users re-authenticate and get their passwords hashed anew under the new algorithm.

Being aware of these pitfalls and considerations equips developers not just for the interview room, but also for building applications that stand strong against security threats in the real world.

References

Practice

Ready to practice Password Hashing?

Answer real questions, get instant feedback, and watch your skill score climb — free. Practice is in English, like real tech interviews.

Try one 👇

Password HashingJunior
0 XP
You are designing a system that needs to securely store user passwords. One key consideration is how to protect those passwords from unauthorized access. You have two choices: use a hashing algorithm that generates a fixed-length output regardless of input, or use one that outputs variable-length hashes based on the input.Which approach should you take to ensure better security for password storage?

↑ Go ahead — pick an answer. This is Skillpato.

Keep learning