4 ms·
Not sure I agree. It seems true that a per-site hash would be enough to defeat _just_ the rainbow table services, but I wouldn't want to have the hacker be able
by iseff 18y ago
Not sure I agree. It seems true that a per-site hash would be enough to defeat _just_ the rainbow table services, but I wouldn't want to have the hacker be able find one password and then be able to distinguish what the salt is for everyone. I would rather have this mitigated by knowing that even if the hacker does brute-force one password, he still won't know the salt for anyone else.
- slackerIII 18y agoYeah, I don't think I made the point I meant to make. Previously, I was under the (silly) assumption that folks who were trying to brute force passwords were running their own rainbow set ups, generating them as necessary based on whatever per-site hash was being used. But the fact that services exist for cracking this sort of thing implies that there are plenty of sites that aren't using salts at all, and by using a per-site salt, you are not the softest target. None of this matters if someone is trying to crack your site in particular, but sometimes you just have to be faster than the slowest gazelle in the herd.
- tptacek 18y agoI'm just going to remind you that if you are talking about your code and you are using words like "salt" and "rainbow table" you have already lost.