2 ms·
Kerckhoffs's principle: A cryptosystem should be secure even if everything about the system, except the key, is public knowledge. So you can assume the algo is
by Robin_Message 14y ago
Kerckhoffs's principle: A cryptosystem should be secure even if everything about the system, except the key, is public knowledge.
So you can assume the algo is public and the salt too (assume someone has a dump of your source code and your database - how do you keep the salt secret? You can't. This is the case where all the effort to protect passwords and use strong hashes is aimed at.)
The solution of "enter your old password" when you enter the new one is simple and doesn't compromise security.
- NLips 14y agoI agree, but "password is not secure if everything about the system, except the key, is public knowledge" is better than "password is saved in plain text".