4 ms·
So can someone explain to me why the downvotes? If the salts are unique to the user wouldn't it be nearly impossible for the hacker to use the hashed pw on othe
by wapz 9y ago
So can someone explain to me why the downvotes? If the salts are unique to the user wouldn't it be nearly impossible for the hacker to use the hashed pw on other sites? (I'm not a web dev but to my understanding that's how it works)
- ktta 9y agoEven if salts are unique to a single user, there's still a possibility where someone determined can get the password. That's because the user specific salts were probably in the same db. This will make it difficult since a brute force attack must be done for every single password. But it is still not impossible.
- sudshekhar 9y ago> If the salts are unique to the user wouldn't it be nearly impossible for the hacker to use the hashed pw on other sites Even if the salts aren't unique, can you explain how can they use the hashed password anywhere? If I give you a hashed password and the salt used, what exactly can you do with it? (apart from brute forcing)
- MichaelGG 9y agoFor instance, you can make a list of the top 100,000 passwords, plus another 1000-per-user variations (based on username or email or whatever). Now run them against all users. You'll get some successes, and now those users are at risk. A password DB breach, salted or not, allows an offline, non-rate-limited, attack on those passwords.