4 ms·
They could definitely use a unique salt if they just check for matches on registration, login, or password change (when they have it in plain text). Still insec
by pcmonk 9y ago
They could definitely use a unique salt if they just check for matches on registration, login, or password change (when they have it in plain text). Still insecure because then you have the info that two different salted passwords have the same plaintext.
- scoot 9y agoBut then what would they match it against?
- jstanley 9y agoIt seems to be looking for exact matches only, so a linear search against the entire user list should be fine, and should quite comfortable be adequate even for thousands of users, depending on hashing algorithm.
- joshuahutt 9y agoBut the rest of the passwords wouldn't be in plain text...
- jstanley 9y agoBut you know the password that has just been entered. Iterate over every hashed password. Hash the plaintext password you know, using the salt from the hashed password. If it's a match, record that the 2 users matched. Loop to next hashed password. If they were plaintext it wouldn't need a linear search because the column could be indexed.
- scoot 9y agoHashed and salted.