Comment on Plex got hacked.

<- View Parent
moseschrute@lemmy.world ⁨1⁩ ⁨day⁩ ago

But if you can solve the hash by generating password guesses, hashing them, and comparing them to the hashed passwords in the database. Say I hash “p@ssword” using the salts sorted in my database. I find that jon@example.com uses “p@ssword”. I then go to Amazon, com, login with Jon’s account, and order a bunch of stuff to my address.

Salt just makes it so I can’t hash “p@ssword” once and find everyone with that password the database. It really only slows me down.

I’m not a security expert, can someone tell me if I got that right?

source
Sort:hotnewtop