4 ms·
From what I understand, salting prevents computing the tables ahead of time and the ability to cross-reference a single password hash against all other password
by deadowl 10y ago
From what I understand, salting prevents computing the tables ahead of time and the ability to cross-reference a single password hash against all other password hashes. It doesn't prevent people who have access to both the salt and the hash from performing the same attack against individual passwords.
- roadnottaken 10y agoYes, that sounds correct. I thought the idea, though, was to make the salt non-obvious for this reason. I would hope people aren't storing passwords in a table with a "salt" column, but I don't really know. But I think you're right: if you know the salts and you want to use this approach to go after a small number of high-value targets it could work.