you are viewing a single comment's thread
view the rest of the comments
[–] [S] 1 point 3 days ago (1 child)

The salt adds nothing

It prevents cross-service re-use, should the original password hash be obtained (if other services used the same system).

Example (MD5 in b64 used for simplicity): Same password is used on website1 and website2. The password is password.
password produces KGdV+tBIacpSMyCszg3GpA== which can be used for both websites.
Now, if website1 adds sbo2 as salt, and website2 addsx3e5, you get:
passwordsbo2 -> d0bd511zpYqG3//3vLGYRQ==
passwordx3e5 -> 788BnQKx7B2KOSju2jviiQ==

So if you are on a corporate network that does MITM (you had to add their root cert) for monitoring, they'll only see a hash for each website separately, without being able to re-use it.
Though that's quite a bit of an edge case, and assumes no client modification or other monitoring.

  • source
  • parent
  • hideshow 1 child comment