Comment on Plex got hacked.

<- View Parent
moseschrute@lemmy.world ⁨1⁩ ⁨week⁩ ago

But if you use a salt that is global to your site/server, you still have this problem: If a hacker cracks “p@ssword” in your database, they immediately know all users that also use “p@ssword”. Imo the biggest benefit of using salts is two users with the same password get different hashes. Right?

I’m not saying using a global salt isn’t better than no salt, but I do think you’re missing out on a huge benefit of using a per hash salt.

source
Sort:hotnewtop