2 ms·
I almost feel as though this is at least half of the point of using salts. We're trying to make things slow, so forcing an attacker to crack the same password
by firebird84 11y ago
I almost feel as though this is at least half of the point of using salts. We're trying to make things slow, so forcing an attacker to crack the same password twice (or more) in cases where it's reused seems beneficial and very cheap. Weak passwords will still be cracked first but it will still require at least SOME work.
- hinkley 11y agoThat was the reason salts were used in /etc/passwd. You couldn't tell if John and James had the same password, and you couldn't tell if John used the same password on multiple machines. Or more critically, if the root password was the same on the entire cluster. As you two have already discussed, it mostly provides herd safety. You can't target the 'weak ones' because all the passwords look roughly the same.