Y
Hacker News
new
|
ask
|
show
|
jobs
by
cluckindan
22 days ago
Or just salt the string with the username before hashing.
1 comments
tybit
22 days ago
That’s what they do, but the TPM pepper is also needed for HMACing in their threat model. Otherwise the attacker just adds the victim’s user id to their hashing process too.
link