4 ms·
The part about salting confuses me. Shouldn't salting remain effective against rainbow tables even when the salting mechanism is known?
by djf1 12y ago
The part about salting confuses me. Shouldn't salting remain effective against rainbow tables even when the salting mechanism is known?
- dnet 12y agoIt should, and they just said "the integrity of weak passwords cannot be guaranteed" -- even the best salting cannot prevent attackers performing brute force attacks; it will be slow, but weak passwords may be cracked in reasonable time.
- wolf550e 12y agocrypto101 says that because of how fast GPUs are at computing hashes, even using long per-user salt is now broken and you must use pbkdf2 or better yet, scrypt.