4 ms·
Why does it matter if hashes are the same? That only tells you the passwords are the same.
by evandwight 5y ago
Why does it matter if hashes are the same?
That only tells you the passwords are the same.
- deleted 5y ago[deleted]
- mindwok 5y agoIf they are the same everywhere, you can precompute a huge database of hashes (called a rainbow table) and simply lookup the hash in the table when breaches occur to find the password. By salting, every provider who stores credentials has different hashes for the same inputs which makes the approach far less attractive at a large scale.
- thaumasiotes 5y ago> If they are the same everywhere, you can precompute a huge database of hashes (called a rainbow table) and simply lookup the hash in the table when breaches occur to find the password. You can do this anyway. But the space requirements of a rainbow table are so large that including an account's username in the password would make a rainbow table completely unfeasible.
- thaumasiotes 5y agoIt doesn't matter at all if one person's hashed password is identical across two of that person's accounts on two different websites. The identical hash will instantly let an attacker (with access to both hashes) know that this person shares the same password across two accounts. But that is of no value; the attacker is going to start by assuming that it's true anyway. Salts are there to ensure that two accounts on the same website which have identical passwords nevertheless have different password hashes.