Video lesson: Store Password Verifiers, Not Recoverable Passwords
Lesson promise
By the end, the learner should be able to explain the core model for store password verifiers, not recoverable passwords, apply it to a concrete input, and identify when its usual shortcut or guarantee stops applying. This is a recording brief; publish it as a playable lesson after the narration and visual sequence have been produced and reviewed.
Narration draft
Password storage should make a stolen database expensive to search. A password hashing function is intentionally slow and memory-intensive compared with a general-purpose hash. Each password needs a unique random salt so equal passwords do not produce equal stored verifiers.
At registration, the service generates a salt and computes a verifier using a password-hashing algorithm with a configured cost. At login, it recomputes the verifier and compares safely. The stored record includes the algorithm parameters so the service can increase cost and rehash after successful authentication.
Encryption is reversible with a key and is not a substitute for password hashing. A fast hash such as plain SHA-256 permits attackers to test guesses too quickly. No password scheme protects weak user choices completely, so rate limits and multifactor options still matter.
Visual sequence
- Put the input and assumptions on screen. Ask the learner to predict the next state before revealing it.
- Animate the representation and show the operation one transition at a time.
- Pause at the boundary case in the companion article and compare the result with the invariant.
- End with the exercise prompt: A database export reveals salts and password verifiers. Explain what salts prevent, what they do not prevent, and why the chosen hash must be expensive to compute.
Companion material
Use the article, trace, and interactive concept flow as the learner’s written and visual references. The video remains planned until an actual playable media URL and reviewed transcript are available.
Related articles
Store Password Verifiers, Not Recoverable Passwords
Password storage should make a stolen database expensive to search.
Latency, Throughput, and the Cost of Coordination
Every system design trade-off is ultimately a balance between doing work fast, doing work often, and paying the cost of making multiple components agree.
What Is a Software System?
A system is not a single program — it is components with boundaries, responsibilities, and failure modes. Learn how to see the box before you design inside it.
New lessons by email
Get new articles and notes on the systems behind everyday software.
One technical dispatch per week. No noise.
Not started
Sign in to save your learning progress.