So, What Is a Login?
Login is a system where the server confirms "you really are the owner of this account." It typically uses two pieces of information — a user ID (email address) and a password — though recent services also widely use fingerprints, facial recognition, and codes sent to a phone (multi-factor authentication).
The Basic Login Flow
How It Works: Passwords Are Never Stored As-Is
The key point is that "the server does not store the actual password." When a user registers, the password is run through a one-way conversion called "hashing" — turned into a scrambled string — and that hash is stored in the database. At login, the entered password is hashed the same way and compared to the stored hash.
Even if the DB leaks, the hash cannot be reversed to get the original password, which limits the damage. However, weak passwords (like 123456) can still be reverse-engineered from their hash — which is exactly why long, complex passwords matter.
Sessions and Tokens
After a successful login, to avoid sending the ID and password with every request, the server issues a "session ID" or "token" — a kind of passphrase. This is stored in the browser's cookie and automatically attached to future requests, so the server knows "this request is from User A."
The key point here is that a session ID or token is a "temporary pass." When a user logs out, is idle too long, or changes their password, the old pass must be invalidated. Forgetting to log out on a shared computer is dangerous because this pass may still be saved in the browser.
Recommended Learning for Teens
Remember this: "Once you can build a login screen yourself, your web development level jumps significantly." Flask + Werkzeug in Python or Express + bcrypt in Node.js are good starting points. Your initial goal is the minimal feature: "register with email and password → log in → display a profile page."
However, using a practice login feature directly in a live service is dangerous. Real services require: limiting login attempt counts, expiry on password reset emails, CSRF protection, Secure and HttpOnly cookie flags, and more. For starters, treat it as a "mini app for understanding the mechanism" and use frameworks or authentication services for any real production work.
Common Pitfalls to Watch Out For
- Storing passwords as plain text in the DB. Always hash them (bcrypt, Argon2, etc.).
- Not using HTTPS. Without encryption, passwords are visible in transit.
- Sending the original password in an email when someone forgets it. This proves the password was stored incorrectly.
How Will This Help You in the Future?
Understanding login correctly helps not just when building web apps, but also when deciding how to protect your own accounts. Passkeys (based on fingerprint/face recognition) are becoming more common, and relying solely on passwords is slowly declining. Being able to explain the difference between passwords, two-factor authentication, and passkeys opens the door to the security field.
What You Can Do Starting Today
- Enable two-factor authentication on one of your SNS accounts (your first real experience with this).
- Search "password hashing bcrypt introduction" and read about how it works for 5 minutes.
- Once comfortable, copy-type a "email registration → login → logout" project in Python or Node.js.
Summary
Check The basic of storing passwords is?