4 ms·
The point of hashing passwords is that the true password is not revealable. The point of salting password hashes is to prevent identical cleartext passwords fr
by worklogin 12y ago
The point of hashing passwords is that the true password is not revealable.
The point of salting password hashes is to prevent identical cleartext passwords from being stored as identical hashes in the database. Salts are often stored in the database, as well.
The point of peppering keeps a database dump from being at all useful for recovering passwords. It make sure that a component of the process of cleartext -> DB entry is not even in the database, requiring something from the app as well.
Why does encryption work here? Because you've already done a one way function on the cleartext -> salted hash. At that point, there is still no way to reverse the process all the way to get the cleartext. By using a two-way encryption function for the pepper portion, you keep the ability to rotate 'peppers' periodically, in case it is leaked, for example.
- ionwake 12y agoThanks for the informative post