Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What do you mean by "the salt is secure"? Hidden in code files vs. stored next to the hashed password?


I apologize if my question was unclear; that's almost certainly because of a lack of expertise on my side.

On one end of the spectrum, I envision the same salt used for every user, allowing for the easy and effective creation of rainbow tables. On the other end, I envision unique salts with many bits of entropy for each user, making rainbow tables technologically infeasible.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: