Should the Salt for a password Hash be “hashed” also?

后端 未结 5 2007
一整个雨季
一整个雨季 2021-01-05 17:29

This I think may be a silly question, but I have become quite confused on what I should do here for the best.

When salting a password hash, should the salt also be h

5条回答
  •  抹茶落季
    2021-01-05 18:13

    It doesn't matter.

    The purpose of a salt is to prevent pre-computation attacks.

    Either way, hashing the salt or using it by itself, results in the same data being added as a salt each time. If you hash the salt, all you are effectively doing is changing the salt. By hashing it first, you convert it into a different string, which is then used as the salt. There is no reason to do this, but it will not do anything wrong if you do.

    You just need to be consistent and use the same method every time or you will end up with a different password hash.

提交回复
热议问题