Hacker News new | ask | show | jobs
by sejje 5116 days ago
This is correct. Salt just defeats rainbow tables. They could still be pre-generated for high-value usernames, though.

Some say that this is most useful in giving the company a more sizeable window in which to react (e.g. force password changes).