Hacker News new | ask | show | jobs
by sixothree 1637 days ago
I assumed the point would be to store all of the salt values ever used server side and never allow reuse of a salt. That way if the hash is captured but has already been used then it is useless.