Re: Values to use for a salt?

Casper Dik <[email protected]>
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
>If you're going to salt, then you need to put the salt at the *END*
>of the password.  Otherwise the cracker can precompute the salt in
>the hashing routine, and there's no speed difference between a salted
>password and an unsalted password.

The "SALT" in the traditional Unix crypt(3c) code is not hashed with the
password; it modifies the algorithm used to crypt the password.

But indeed, the commonly used md5 hashes do hasg the salt after
the password.

Casper
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.