Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Even with a salt you can still tell if a password is reused. You just have to use the same salt.


If you are using the same salt on multiple passwords you are not doing it properly. It is supposed to be almost a nonce. 1 random salt per password.


That is the standard way of doing it, yes. However not every non-standard implementation is insecure.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: