3 ms·
Is it worth it to salt in scenarios when the passwords (actually tokens) themselves are guaranteed to be unique and instead only use pepper?
by blntechie 6y ago
Is it worth it to salt in scenarios when the passwords (actually tokens) themselves are guaranteed to be unique and instead only use pepper?
- couchand 6y agoShort answer: if they are unique because they're a small sample from a large space (e.g. UUID v4) no salt is needed. If they're unique but maybe predictable, salt.
- blntechie 6y agoThanks! Yes, they are random GUID-like values and are short lived (2-4hrs). Had a need to store them for a reason and decided to only add pepper to hash considering they are unique and short lived anyway.