[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Hash salt (was Re: BCRYPT - Why not using it?)



On Thu, Apr 07, 2011 at 06:52:42AM +0200, Martin Ågren wrote:
> In this particular scheme, it appears ('foo','salt') has the same hash
> as ('foosalt',''). In a serious application, hopefully the wheel
> wouldn't be reinvented in this way, but some well-studied, thoroughly
> scrutinized approach would be used. :) But as a toy example it works,
> sure!

The point was to illustrate how a password and salt work to create a unique
hash. Sure, I could have covered all the details on the specific
/etc/shadow implementation, but then we wouldn't see the forest from the
trees.

At any event, point taken.

--
. o .   o . o   . . o   o . .   . o .
. . o   . o o   o . o   . o o   . . o
o o o   . o .   . o o   o o .   o o o

Attachment: signature.asc
Description: Digital signature


Reply to: