Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Salted hashes are better than unsalted hashes.


Against a GPU that can calculate five million hashes per second your salt isn't worth the paper it's printed on.


I don't know about you, but personally I think "crack one person's password in one day" is a much better situation than "crack everyone's password in one day".


That's why you use a different salt per user.


So we should just store the password in plain text then!! Or we could use the honor system, with no password!!


Who prints out password salts anyway?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: