4 ms·
A proper KDF is more important if you are trying to break a specific user's password. It will simply take too long to try any reasonable number of attempts. H
by davis_m 12y ago
A proper KDF is more important if you are trying to break a specific user's password. It will simply take too long to try any reasonable number of attempts. However, in the event that you have a large database leak individual salts become just as important. When looking thousands of users, unsalted hashes allow attackers to start with the most common passwords used and compare them to the entire leaked database in one try.
- kasey_junk 12y agoAre there any proper KDFs that don't include a random salt?
- boogboog 12y agothis whole discussion is a red herring. Of course all current KDFs include salting as a form of key stretching. That's because no one designing them is writing off rainbow table attacks.