Using a hash of what you are hashing as a salt?

前端 未结 6 1835
情话喂你
情话喂你 2021-01-24 19:40

Say a user registers for your site, you hash the password they have chosen then use that hash as a salt and rehash their password with that salt.

Example:



        
6条回答
  •  悲&欢浪女
    2021-01-24 20:21

    This is key strengthening (http://en.wikipedia.org/wiki/Key_strengthening), a nice technique that nonetheless does not substitute for actual salt. It will not protect you against a rainbow table written with this double-hash function.

提交回复
热议问题