Salting: Is it reasonable to use the user name?

前端 未结 6 2004
礼貌的吻别
礼貌的吻别 2021-02-20 16:53

I am debating using user-names as a means to salt passwords, instead of storing a random string along with the names. My justification is that the purpose of the salt is to prev

6条回答
  •  醉梦人生
    2021-02-20 17:24

    If you use the username as password and there are many instances of your application, people may create rainbow tables for specific users like "admin" or "system" like it is the case with Oracle databases or with a whole list of common names like they did for WPA (CowPatty)

    You better take a really random salt, it is not that difficult and it will not come back haunting you.

提交回复
热议问题