Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Salting means that you must crack each key individually. It slows things down marginally in the long-run and at least precludes someone form using Google as your rainbow table. Have you ever tried searching for MD5 hashes of things like 'password' or 'pass123'? It's terrifying.


Looks like it wasn't clear that my question was rhetorical. My point was that some secret mangling on top of a standard hashing algorithm doesn't offer more protection than salting.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: