What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use a slow, adaptive password-hashing algorithm—not plaintext, reversible encryption, or SHA-256 by itself. For new systems, prefer Argon2id where a maintained library supports it; generate a unique cryptographically random salt for each password; store the algorithm and its parameters with the resulting verifier; and verify through the library’s dedicated function. The right cost depends on your server and expected login concurrency, so benchmark it under realistic load.

Choose a password-hashing algorithm

Password hashing is intentionally expensive: it makes each password guess cost an attacker time and, for memory-hard algorithms, substantial memory. A fast general-purpose digest such as SHA-256 alone is unsuitable because it allows guesses to be tested rapidly. Use a password-hashing function designed for this purpose.

Algorithm When to choose it Configuration guidance Trade-offs
Argon2id Preferred for new systems when a maintained implementation is available. OWASP’s current minimum is 19 MiB memory, 2 iterations, and parallelism 1. RFC 9106 (2021) gives two recommended profiles: t=1, p=4, m=2^21 KiB (2 GiB), with a 128-bit salt and 256-bit tag; or, for less memory, t=3, p=4, m=2^16 KiB (64 MiB), with the same salt and tag sizes. Memory-hard and tunable, but memory requirements must fit the service’s capacity and concurrency.
scrypt Use if Argon2id is unavailable. OWASP’s current minimum: N=2^17, r=8 (1,024 bytes), p=1. Memory-hard; check runtime and library support and benchmark for the target environment.
bcrypt Primarily a legacy choice when Argon2 and scrypt are unavailable. OWASP advises a work factor of at least 10. Its common maximum input is 72 bytes. Input-length limits can cause long passwords to be truncated or rejected depending on the implementation. Understand the specific library’s behavior before adopting it.
PBKDF2 Use when FIPS-140 requirements apply, subject to the applicable runtime provider and compliance requirements. OWASP advises PBKDF2-HMAC-SHA-256 with at least 600,000 iterations. CPU-intensive rather than memory-hard; provider support and operational performance matter.

The OWASP values are baselines, not universal optimal settings. RFC 9106’s Argon2id profiles are separate recommendations, not values to mix casually with OWASP’s baseline. Choose a profile your service can sustain and load-test it.

Sources: OWASP Password Storage Cheat Sheet; RFC 9106.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
MOSA BEAR Password Keeper Book with Alphabetical Tabs,4.3"x5.7" Small Password Books for Seniors Password Notebook for Internet Website Address Log in Detail(Dark Blue)
  • 【Tired of constantly searching for or resetting your passwords?】 MOSA BEAR password keeper book is the perfect solution for you! This password book provides a dedicated place to securely store all your important website addresses, emails, usernames and passwords, ensuring your information is protected and easy to find. The well-designed log pages help you manage multiple accounts in a systematic way, saying goodbye to password confusion.
  • 【Premium Design & Password Security】 The password book with alphabetical tabs features an anonymous cover design with no title on the cover, effectively avoiding information exposure. The password keeper design is specifically designed with password security in mind, providing space to record password hints instead of writing directly on the password itself, further protecting your important information.
  • 【Simple Layout and Plenty of Space】The 160-page password logbook is designed to provide ample space to record passwords and other important information. It can store up to 414 passwords. In addition, it provides extra pages to record other information, such as email setup, card information, computer operating system information, software licenses, and more. The journal also includes 3 blank pages at the end for you to add additional notes.
  • 【Palm-sized Size & Premium Quality】 This password notebook has an ideal size, 4.3" x 5.7", for carrying around, whether in a purse or pocket. Its sturdy glue binding allows the notebook to unfold smoothly and is more comfortable to use. The inner pages are made of high-quality 100GSM thick paper, which can effectively reduce ink penetration and ensure a cleaner and neater writing effect. The overall design takes into account both portability and durability, making it an ideal choice for recording important passwords.
  • 【A-Z Tabs for Quick Search 】Our password book comes with alphabetical tabs to help you find the password you need quickly and easily. Alphabetically organized tabs ensure that you can quickly flip to the right section, saving you the time and hassle of searching for your password.

Generate and store a salted verifier

For every password, use a fresh, cryptographically random salt. A salt is not secret: store it with the verifier. Unique salts ensure that users with the same password do not have identical stored values and frustrate precomputed hash tables. Many high-level libraries generate salts and encode the salt and cost parameters automatically. With a lower-level key-derivation API, your application must generate and save the salt and all parameters needed to reproduce the derivation.

Store a self-describing, versioned verifier where possible. It should identify the algorithm and version, salt, cost parameters, and derived output. During login, use the record’s parameters to verify the submitted candidate; do not silently substitute current settings when checking an older record.

Rank #2
Sale
WEMATE Password Book with Lock Keeper Book for Seniors 4.33x6.18in Black
  • 🔒 Password Book with Lock: Are you looking for the lockable password book to keep your passwords safety? WEMATE Password keeper book has a great way to organize passwords. For added security there has a creative metal lock with 0-9 three-digit combinations, and hundreds of password combinations highly confidential to help you secure internet passwords and keep your information safe and organized.
  • ✍Warm Notes: Please remove the black buckle before using the password book with lock
  • ✍ More Password Space with 600+: WEMATE password organizer with a huge space of up to 600+ website usernames & passwords to store all your account & website login details in one place, fully protecting your personal privacy, and keeping online website account information & user data safe.
  • ✅ Never Forget Your Password Again: Password notebook organizer with durable leather, and it looks like one of those writing journals, so no one will know it is a password book. However, we still recommend keeping the internet password book in a secure place, such as a locked drawer or a bookshelf full of books.
  • ✅ 100% Satisfied Service: We hope that our small password book with lock will help you store your passwords efficiently. if you are having any quality issues or are not completely satisfied with your password keeper book for any other reason. Reach out to us via an Amazon message and we will be happy to help you!

A pepper is different: it is a shared secret applied in addition to per-password salts. If used, keep it outside the password database, such as in a secrets vault or HSM. Peppering is defense in depth, not a replacement for password hashing. Because a pepper cannot be rotated using stored hashes alone, compromise or rotation may require password resets. OWASP’s guidance on salts and peppers explains these distinctions.

Verify a password hash safely

  1. Look up the user’s stored verifier.
  2. Pass the candidate password and stored verifier to the password-hashing library’s dedicated verify function. The verifier’s encoded data should supply the original salt and parameters.
  3. If using a raw KDF instead of a self-describing password-hash library, derive the candidate output with the stored salt and parameters, then compare the bytes using a constant-time comparison function.
  4. After successful authentication, check whether the stored algorithm or cost is below current policy. If so, hash the candidate password with current settings and replace the verifier.

Do not compare raw derived values with ordinary string equality when a constant-time comparison is available. A high-level verify API is generally preferable because it handles parsing and comparison details for the format it supports.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Password Book with Alphabetical Tabs, Password Keeper for Seniors 5.3"x7.7"
  • 【Featured A-Z Tabs & Untitle for Security】Our password books have recognizable alphabetical tabs with the colorful design allow you to locate quickly and save time. The anonymous cover of our password keeper is unobtrusive and stays secure.
  • 【Premium Quality & Perfect Size】This password journal features a eco-leather hardcover and 100gsm no-bleed paper, equipped with an elastic band, inner pocket, pen loop and bookmark. It comes in medium format (5.3 x 7.7 inches) which is the perfect size you need.
  • 【Clean Layout & Plenty of Space】 Each tab has 6 pages with 4 entries per page and contains more than 552 passwords in our password organizer. This password notebook also provides more password space in case you need to change your password.
  • 【Perfect Organization & Safe Placement】We ensure this password log book provides you with a secure space to keep passwords and web addresses. You won't have to worry about passwords being leaked or hacked.
  • 【Thoughtful Gift & Warm Heart】 Considering for practical gifts for family or friends? Our specially designed internet password book is sturdy and easy to use. Ideal for any occasion, it's a gift that truly shows care.

Implementations differ by language

The four ecosystems do not offer an identical built-in Argon2id workflow. Prefer a maintained password-hashing library that creates and verifies a self-describing hash, and confirm support for the runtime version and provider you deploy.

Node.js

Node.js v26.7.0 documents asynchronous crypto.argon2 and crypto.scrypt, plus PBKDF2. Node documents Argon2 as added in v24.7.0, so older Node releases may not expose that API. Its Argon2 API accepts the password message, salt (nonce), parallelism, output length, memory, and passes. Use asynchronous APIs in servers and load-test them. Node also warns that PBKDF2 uses libuv’s threadpool, which can affect application performance.

Rank #4
Sale
Elegant Password Book with Alphabetical Tabs - Hardcover Password Book for Internet Website Address Login - 5.2" x 7.6" Password Keeper and Organizer w/Notes Section & Back Pocket (Turquoise)
  • NEVER FORGET A PASSWORD AGAIN: Almost every App. has a password, it is almost impossible to remember all the password log in details. This password book is specifically designed to help you create secure passwords and store all your passwords safely in one place. You will never forget your password log-in details again with this password keeper.
  • ALPHABETICAL A-Z TABS FOR QUICK ACCESS: Alphabetical tabs design allows you to store your passwords alphabetically so you can find what you want faster, no more annoying searches!
  • ANONYMOUS WITHOUT ANY TITLE: On the outside, this password notebook organizer looks just like those writing journals, there is no title listed on the cover, so no one would know it's a password book. But we still recommend keeping the internet password logbook in a safe place such as a locked drawer or a shelf full of books.
  • THICK NO-BLEED PAPER: This 5.2" x 7.6" password book contains 74 sheets of thick 120gsm paper that resists ink smearing, say goodbye to those cheap password books that bleed ink!
  • PREMIUM QUALITY & PERFECT MEDIUM SIZE: This password journal comes with a high-quality leatherette hardcover, an elastic band, pen holder, ribbon bookmarker, and inner accordion pocket. It measures 5.2 inches wide and 7.6 inches long, which is the perfect size for your needs.

Source: Node.js v26.7.0 Crypto documentation.

Python

Python 3.13’s hashlib provides pbkdf2_hmac and scrypt, accepting bytes-like password and salt inputs. Its documentation recommends a salt of about 16 or more bytes from a proper random source such as os.urandom(); iteration guidance depends on hardware and digest. PBKDF2 availability requires an OpenSSL-enabled build. The standard library documentation does not provide an Argon2 password-hash-and-verify abstraction, so use a maintained Argon2 library if choosing Argon2id.

Source: Python 3.13.15 hashlib documentation.

Go

golang.org/x/crypto/argon2 provides Argon2 derivation primitives, while golang.org/x/crypto/bcrypt provides bcrypt password-generation and comparison helpers. Argon2’s lower-level API leaves your application responsible for encoding parameters and salt and performing a safe comparison. Pin and review the package version used by your application.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
MOSA BEAR Password Keeper Book with Alphabetical Tabs,4.3"x5.7" Small Password Books for Seniors Password Notebook for Internet Website Address Log in Detail(Black)
  • 【Tired of constantly searching for or resetting your passwords?】 MOSA BEAR password keeper book is the perfect solution for you! This password book provides a dedicated place to securely store all your important website addresses, emails, usernames and passwords, ensuring your information is protected and easy to find. The well-designed log pages help you manage multiple accounts in a systematic way, saying goodbye to password confusion.
  • 【Premium Design & Password Security】 The password book with alphabetical tabs features an anonymous cover design with no title on the cover, effectively avoiding information exposure. The password keeper design is specifically designed with password security in mind, providing space to record password hints instead of writing directly on the password itself, further protecting your important information.
  • 【Simple Layout and Plenty of Space】The 160-page password logbook is designed to provide ample space to record passwords and other important information. It can store up to 414 passwords. In addition, it provides extra pages to record other information, such as email setup, card information, computer operating system information, software licenses, and more. The journal also includes 3 blank pages at the end for you to add additional notes.
  • 【Palm-sized Size & Premium Quality】 This password notebook has an ideal size, 4.3" x 5.7", for carrying around, whether in a purse or pocket. Its sturdy glue binding allows the notebook to unfold smoothly and is more comfortable to use. The inner pages are made of high-quality 100GSM thick paper, which can effectively reduce ink penetration and ensure a cleaner and neater writing effect. The overall design takes into account both portability and durability, making it an ideal choice for recording important passwords.
  • 【A-Z Tabs for Quick Search 】Our password book comes with alphabetical tabs to help you find the password you need quickly and easily. Alphabetically organized tabs ensure that you can quickly flip to the right section, saving you the time and hassle of searching for your password.

Source: Go Argon2 package documentation and Go bcrypt package documentation.

Java

Java SE 25 documents PBEKeySpec and SecretKeyFactory, which provide lower-level password-based derivation primitives such as PBKDF2 when the runtime provider supports the requested algorithm. They do not by themselves provide a complete password-hash encoding and verification workflow: preserve the salt and parameters and compare outputs safely. For Argon2id, use a maintained library rather than assuming the standard JDK includes an Argon2 API.

Source: Java SE 25 PBEKeySpec documentation and Java SE 25 SecretKeyFactory documentation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Tune costs and upgrade hashes over time

There is no universally ideal work factor. OWASP advises balancing the cost imposed on attackers against the time and resources your login service can sustain; overly expensive verification can itself create denial-of-service risk. Its general guidance is to aim for less than one second for a password-hash calculation, but that is not a guarantee or a suitable target for every service. Measure on the actual server, with realistic concurrent logins, CPU and memory limits, and latency requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When policy changes, successful login is the practical opportunity to upgrade a hash because the candidate password is then available. Verify using the record’s old algorithm and parameters, derive a new verifier using current policy, and replace the old record. Track which accounts still have old verifiers so you can manage remaining records through a defined migration, expiration, or reset policy.

Source: OWASP Password Storage Cheat Sheet.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.