3 ms·
Or just salt the string with the username before hashing.
by cluckindan 3mo ago
Or just salt the string with the username before hashing.
- tybit 3mo agoThat’s what they do, but the TPM pepper is also needed for HMACing in their threat model. Otherwise the attacker just adds the victim’s user id to their hashing process too.