Password hashing
Password hashes allow verification without storing plaintext.
What it is
Password hashes allow verification without storing plaintext.
When to use it
Use adaptive framework/PHP password functions.
Syntax
// Bad: md5($password) or plaintext
// Good:
$hash = password_hash($password, PASSWORD_DEFAULT);
$valid = password_verify($password, $hash);Example
use Illuminate\Support\Facades\Hash;
$user->password = Hash::make($validatedPassword);
$user->save();
$valid = Hash::check($candidate, $user->password);Common mistakes
Do not invent salts or algorithms; hashing is not reversible encryption; avoid silently truncating long passwords.