Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What if a site uses 128-bit salts generated by a good (perhaps hardware-based) RNG?


That will remove pre-computed rainbow tables from the equation.


Only really for the time being (and a considerable time to come, Quantum and Biological computing enhancements notwithstanding) but for a salt that big it makes far much more sense to use a key derivation function as you're effectively generating two keys otherwise (one user generated, the other - salt - via PRNG).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: