4 ms·
>To be secure the salt must be stored in a different location from the stored hashes and the salt value should not be statically visible in the source code prov
by Novashi 8y ago
>To be secure the salt must be stored in a different location from the stored hashes and the salt value should not be statically visible in the source code provided a source code compromise.
This is outdated though. You don't need to take extra steps to secure the salt if you move to a good hash.
- RJIb8RBYxzAMX9u 8y ago"Hashing" is unfortunately a very overloaded term. Even searching for "password hashing" gave me pretty bad results for the top hits. "Key derivation function" (KDF) gave much better results.