Why Are Our Passwords Almost Impossible to Crack?
- cybersecurite
- developpement
- django
- mot de passe
- mit
- CTSS

Today, entering a password to access a computer, an application, or an account has become an ordinary gesture. Yet, this mechanism is the result of several decades of evolution.
And it all begins at MIT, in 1961.
The Birth of the Password
At the time, MIT had only one computer, shared between students and researchers. To improve its use, Fernando Corbató developed the CTSS (Compatible Time-Sharing System), one of the first systems that allowed multiple people to use the same computer interactively.
The system allowed each user to have their own files.
But a problem quickly emerged: how could one user be prevented from accessing another user's files?
The solution was simple: an account associated with a password.
This was one of the earliest forms of a computer password.
But there was a major problem: passwords were stored in plain text in a file. Anyone who gained access to that file could therefore retrieve every account's password.
This is exactly what Allan Scherr, an MIT student, did in what is considered one of the first computer password thefts.
From Passwords to Hashing
A few years later, in 1970, Robert Morris, from Bell Labs, proposed a much safer approach: instead of storing the password directly, the system would store a cryptographic fingerprint, known as a hash.
The principle is simple:
password -> hash function -> fingerprint
When logging in, the password provided by the user is hashed again. The system then compares the two fingerprints.
The original password therefore no longer needs to be stored.
But a new weakness emerged: the same password always produces the same hash.
Attackers could then precompute millions of passwords and their corresponding hashes in databases known as rainbow tables.
The Role of Salting
To counter this attack, a random and unique value called a salt is added to the password before hashing.
password + salt -> hashing -> fingerprint
As a result, two users with exactly the same password can have completely different hashes.
Salting makes attacks using precomputed tables much more difficult.
And What About Django?
In Django, this mechanism is handled automatically. By default, Django uses PBKDF2 with SHA-256, along with a certain number of iterations and a unique salt.
A value stored in the database can look like this:
<algorithm>$<iterations>$<salt>$<hash>
When logging in, Django retrieves this information, applies the same process to the password provided by the user, and checks whether the fingerprints match.
Just a String of Characters?
In the end, a password is much more than a string of characters.
Behind a simple "Log in" button lies a history of resource sharing, human curiosity, security vulnerabilities, cryptography, and algorithms.
And above all, one essential idea: computer security often evolves because someone finds a new way to bypass what existed before.