Birdwatch Note Rating
2024-08-01 03:40:10 UTC - HELPFUL
Rated by Participant: A1000BB065FE490FA26E13D13F8B5FE55C444E0FD71FA77C4729FD08DFD9F9A7
Participant Details
Original Note:
Storing plaintext passwords is insecure. Always hash passwords using bcrypt, Argon2, or PBKDF2 at least. Example: ```python import bcrypt hashed = bcrypt.hashpw(password.encode('utf-8'), bcrypt.gensalt()) bcrypt.checkpw(password.encode('utf-8'), hashed) ``` https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html https://pages.nist.gov/800-63-3/sp800-63b.html#sec5
All Note Details