|
|
|
|
|
by mistercow
4504 days ago
|
|
It still confers a negligible advantage. If the attackers have gotten into your data server, why shouldn't they be able to get into your application server just as easily? All you're doing is slightly inconveniencing the attacker before they can derive your salt wholesale. Always remember: a secure system is secure even if the attacker can see your source code. Any work you do based on assuming the opposite is a waste of time. |
|