4 ms·
I'm confused by their claim of hashing and THEN salting authentication codes. On the server-side, we don't store the authentication code in plaintext.
by adam-f 13y ago
I'm confused by their claim of hashing and THEN salting authentication codes.
On the server-side, we don't store the authentication
code in plaintext. We hash it with PBKDF2 / SHA-256,
salt it, then store it.
- tashmahalic 13y agoIt's a salted hash. That page is corrected, thanks.