HN2new | past | comments | ask | show | jobs | submitlogin

I fail to understand why salting is bad. Seems like he's saying it's not a cureall. We knew that. But it's at least marginally better than not salting and it's easy, so why the hell not?


Yeah, salting definitely isn't bad, in fact it's actually essential. What the author is saying is that it's not enough - salting won't save you when your attacker can test 10s or 100s of thousands of hashes a sec. The article could have been phrased better.


What he's saying is that a salt should be a no-brainer. FTA: "Storing passwords as unsalted hashes is a grievous mistake of course, and breaches disclosing poorly stored passwords are still too common."

He's simply saying that a salt isn't enough to keep your passwords secure - you should also be using a slow hashing / memory intensive hashing function.


Nobody's saying salting is bad, the blog is saying that salting is a given, if it's not you don't belong anywhere near passwords.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: