|
|
|
|
|
by benrutter
317 days ago
|
|
That's still not perfect though! Most leaked passwords online come initially from leaked hashes, which bad actors use tools like hashcat to crack. If your user has a password like "password123" and the hash gets out, then the password is effectively out too, since people can easily lookup the hash of previous cracked passwords like "password123". |
|
[0] https://en.wikipedia.org/wiki/Salt_(cryptography)