A good app can't email you your own password — that's the feature

If a service can show you your password, it stored it wrong. What a hash is, why "salt" matters, and the one red flag that tells you an app is unsafe.

Aliteq
Syntax · Build Editor

You now understand

A safe app stores a one-way hash, never your actual password

You now understand

It checks login by hashing your input and comparing hashes

You now understand

A unique salt per user, plus a deliberately slow algorithm, is what makes a leaked database hard to crack

What this means for your app

You shouldn't hand-roll this; a provider like Supabase Auth hashes and salts for you. The red flag to watch for: any app that can email you your existing password, or shows it in a settings screen,…

Aliteq

Read the full story

A good app can't email you your own password — that's the feature

Read the full story on Aliteq