9 ms·
Wouldn't you just need to hash the password and do a lookup on the table to see how many results were returned?
by Kadrith 16y ago
Wouldn't you just need to hash the password and do a lookup on the table to see how many results were returned?
- aamar 16y agoIf you are generating a per-password salt, that won't work. In order to find prior occurrences of a given password, you would have to hash the password for every salt value that you've ever used. And since you're using BCrypt[1], that will be very slow. [1] http://codahale.com/how-to-safely-store-a-password/ http://codahale.com/how-to-safely-store-a-password/