Hacker News new | past | comments | ask | show | jobs | submit login

Yes, salting has a role to play. That is not the point. The point is that use of a weak underlying Key Derivation Function makes the benefits of salting nearly moot.

To fully spell it out: MD5 is a very weak KDF.

I would recommend looking into the KDFs mentioned in the comments here as alternatives: PBKDF2, bcrypt, scrypt.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: