3 ms·
forgive me, I haven't worked with a good hashing mechanism before. How can it "salt for you" without you providing the salt? This question is operating on the
by GhotiFish 12y ago
forgive me, I haven't worked with a good hashing mechanism before.
How can it "salt for you" without you providing the salt?
This question is operating on the presumption of a unique salt per user.
- ryan-c 12y agoA lot of password hashing APIs have two calls - one where you provide the password (and possibly work factor) and it returns a hash that includes a randomly generated salt, and another where you pass in the hash (which includes the salt and work factor if any) and the password which returns true/false.
- kasey_junk 12y agoI was skipping some complexity. Something like b/scrypt are more than just hashing. They are key derivation functions, which look similar to hash functions on their inputs. bcrypt for instance generates a random salt on the input and stores it in the output. http://stackoverflow.com/questions/6832445/how-can-bcrypt-have-built-in-salts http://stackoverflow.com/questions/6832445/how-can-bcrypt-ha...