Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If the 'common-salt' length is counted as part of the total salt length, then an attacker who knows the common part of the salt could more easily generate a rainbow table (as half the salt is predictable).

If it's just added (but not counted), then it'd be like asking for a password (XXX) and always prepending something to it before hashing (saltyXXX) -- at which point -- what value are you getting out of it?

I don't believe an /uncounted/ common salt is harmful - but I don't see any use on its face.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: