|
|
|
|
|
by by
5658 days ago
|
|
It is a salt collision not a hash collision. No, clearly one would not matter, hence staying below that would be entirely safe against a salt collision inside your database. But if it was feasible to store 10^32 rainbow tables you should make it longer. Ah, it should probably be longer. I think 128 bit salts would be more sensible. |
|
I just ran a quick shell script over the database file. There are only 3329 password collisions. Of 700,000+. Sure, a bigger salt could have reduced that. But was that in any way the cause of the problem? No.