9 ms·
My guess it they have a static salt for all passwords in code somewhere (newbie mistake I made years ago).
by dreadlordbone 5y ago
My guess it they have a static salt for all passwords in code somewhere (newbie mistake I made years ago).
- jpalomaki 5y agoStatic salt is called pepper [1]. It's not a bad idea - but it would be better used with the regular salt. Some people don't seem to like the idea, but I think it adds an easy additional layer of protection. At least in the past many of the password leaks seemed to be due SQL injections and only leaking the database content. Pepper stored in the code would have protected the passwords. https://en.wikipedia.org/wiki/Pepper_(cryptography) https://en.wikipedia.org/wiki/Pepper_(cryptography)