4 ms·
I think you need to make sure that each user has a unique salt. If you happen to assign me the same salt as another user then either my or their password will
by KayEss 14y ago
I think you need to make sure that each user has a unique salt.
If you happen to assign me the same salt as another user then either my or their password will unlock either account and the attacker only needs to guess the weaker of the passwords.
- zaroth 14y agoAbsolutely correct. A 'salt' by definition, is always random. For example, you could use a 32-byte salt with scrypt and you would get back a 32-byte hash. Both are equally unlikely to ever collide (see numbers in the article) even with trillions of entries in the table.
- KayEss 14y agoWith this scheme random isn't quite enough though, it needs to be unique as well doesn't it?
- dchest 14y agoChances of generating two random 32-byte strings that collide are so tiny that you can as well say that they are unique.
- deleted 14y ago[deleted]