Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
mygo
on Feb 26, 2018
|
parent
|
context
|
favorite
| on:
Apple confirms it uses Google cloud for some of iC...
Even with a salt you can still tell if a password is reused. You just have to use the same salt.
wisenull
on Feb 27, 2018
[–]
If you are using the same salt on multiple passwords you are not doing it properly. It is supposed to be almost a nonce. 1 random salt per password.
mygo
on Feb 28, 2018
|
parent
[–]
That is the standard way of doing it, yes. However not every non-standard implementation is insecure.
Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: