Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Brightman
Feb 24, 2005

I've seen fun you people wouldn't believe.
Tiki torches on fire off the summit of Kilauea.
I watched disco balls glitter in the dark near the Brandenburg Gate.
All those moments will be lost in time, like crowds in rain.

Time to sleep.

rolleyes posted:

I'm confused by it tbh. Unless I'm missing something, under normal circumstances salting a hash shouldn't prevent you from comparing hashed values (especially for the same user) because you'd normally use the same salt value for that user all of the time. As I understand it, the point of a salt isn't to make passwords hard to compare within your own database or organisation, it's to protect against rainbow table attacks if your database is compromised externally.

They're saying if 15 different people used the same password they'd want to ban it, but they salt, and that's different for each user, so it's a no go. The goal is to eliminate any kind of top 10 password list or at least limit it to only 14 instances of "password1" or "adobeadobe".

Adbot
ADBOT LOVES YOU

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply