Hacker News new | ask | show | jobs
by fluidcruft 278 days ago
You can also have a system salt(s) that are not stored with the database, so that if someone accesses the database they have to guess password and two salts, one of which they hopefully do not have via the same penetration.