Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Do you know what hash was used, if the passwords were salted and if so, if the salt is secure?


What do you mean by "the salt is secure"? Hidden in code files vs. stored next to the hashed password?


I apologize if my question was unclear; that's almost certainly because of a lack of expertise on my side.

On one end of the spectrum, I envision the same salt used for every user, allowing for the easy and effective creation of rainbow tables. On the other end, I envision unique salts with many bits of entropy for each user, making rainbow tables technologically infeasible.


I'm not on the team that handles passwords so can't comment. Sorry.


Hmmm, please ask the team that handles passwords and let us know.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: