3 ms·
Self-salting with the domain name serves another purpose: prevents you from using the same password across multiple sites. If your password is "password_linked
by AncientPC 14y ago
Self-salting with the domain name serves another purpose: prevents you from using the same password across multiple sites.
If your password is "password_linkedin", it's fairly obvious what the salt is. However, most released passwords are not heavily scrutinized. It's most likely that those using exposed passwords will instead try user@email.com / password_linkedin elsewhere.
You can also easily change self-salt so it doesn't fit any obvious pattern. What I do is a strong base password, then self-salt with the domain name. For example:
Mk3+e1_T2iei
I'm using "Mk3+e1_T" as the base password, "2" as a divider, and "iei" are the first 3 vowels of a domain name (LinkedIn in this example).