3 ms·
Why not just use the phrase+password as a password?
by TimMontague 17y ago
Why not just use the phrase+password as a password?
- deleted 17y ago[deleted]
- deleted 17y ago[deleted]
- e1ven 17y agoBecause that doesn't give you security if the site is compromised. For example, if my Phase+password combination is RootGod+Facebook.com it wouldn't take very long for someone to realize that RootGod+Gmail.com would also likely work there.
- pyre 17y agoI thought that the Password+Site combo assumed the usage of SHA1 or MD5, though I know that this doesn't work for some sites (with max password limits). Maybe CRC32 in those cases?
- dfox 17y agoCRC32 is bad way to hash anything, if you want secure hash of some obscure length, just truncate output of say SHA-256 (by the way, SHA-224 is exactly this: truncated output of SHA-256).