4 ms·
Could you explain why? The post below explains about how two users really shouldn't share the same password, and if they do, it's easily crackable - that makes
by ssafejava 13y ago
Could you explain why? The post below explains about how two users really shouldn't share the same password, and if they do, it's easily crackable - that makes sense. However, if you had a list of 100,000 passwords and did, say, a brute force attack of all passwords with letters, numbers, and special characters to a length of 8, without salted hashes you would be able to run that brute force once and grab every password matching the criteria. With salts, you would have to run it once per salt. Am I off on that?
- jacques_chester 13y agoYou're not wrong, but: 1. If you're using salt, it implies you chose to roll your own key function using hashes. That's a bad idea, because: 2. GPUs can produce so many combinations per second that the difference between salted and unsalted is basically indistinguishable for smart attackers.