Password Hashing and Salting
Discussions focus on the importance of properly hashing and salting passwords for security, debating whether a breach involved unsalted hashes vulnerable to rainbow table attacks and recommending practices like bcrypt.
Activity Over Time
Top Contributors
Keywords
Sample Comments
hashing and salting wouldn't really have helped in this situation
From the information available it appears the passwords were hashed but not salted.
Use a salted hash like everybody else does with passwords?
Doesn't this assume the passwords aren't hashed and salted?
If they are properly hashed and salted, they can not.
That's the point, take a look into salting + hashing passwords
Nope they don't know your password, they just have the salted hash.
Why not, since you're only storing a fixed-length hash of the password?
Hashing should be done with salt for precisely that reason.
That's secure as long as the hash is (securely) salted.