Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Salting was originally important as a defense against rainbow tables - which are more or less obsolete with GPUs that can crank through trillions of hashes per second. The real reason that bcrypt is a better way to store a password isn't just because it uses a salt - it's because its designed to be slow and to use a bunch of memory which makes it much harder to brute force.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: