3 ms·
Salts are suppose to be considered public. For the most part, they are defenses against rainbow tables and to make an attacker have crack each password individu
by nlco 15y ago
Salts are suppose to be considered public. For the most part, they are defenses against rainbow tables and to make an attacker have crack each password individually.
- zagaberoo 15y agoExactly; Having a secret hash is just another example of futile security through obscurity. You want an attacker to be able to know as many parts of the puzzle as possible and still be thwarted.
- barefoot 15y agoAgreed, but an important part of the article was that even public salted md5 passwords are ineffective.