|
|
|
|
|
by rythie
6250 days ago
|
|
"Hashing and salting a password removes absolutely ewvery security weakness in terms of directly extracting the password. No need for layered security and potentially complex uneeded encryption/decryption in your app. Safe, secure. end of the matter :)" It is seriously worrying that you believe this. Cracking hashed passwords offline is no big deal on a single machine unless you have really strong password policy - you know, the type of password no real regular user would even enter. |
|
Allowing password security to depend on what the user enters IS silly - but who would! 32haracter salts and sha256 is going to produce a fairly uncrackable password.
Even if you know the salt and the salting algorithm (because simply appending a salt is also silly) it can still take a while :)
Im not talking about just sticking "MYSECRETSTRING" on the end of every password and sha1-ing it :)