Password Salts
#9

Surely no matter how you salt your passwords, they can be cracked using a rainbow table once you know the 'format'?

For example, going by Kreatyve's example:

Mike
'password'

Mipasswordke

In the table, the player's name and password hash are stored. If someone wants my password, all they have to do is make a rainbow table of 'Mi[?????]ke'. There's only one variable part. It's exactly the same as not having a salt at all.

How long exactly would it take to make a rainbow table anyway?
Reply


Messages In This Thread
Password Salts - by MP2 - 26.06.2013, 16:39
Re: Password Salts - by MP2 - 26.06.2013, 16:59
Re: Password Salts - by MP2 - 26.06.2013, 17:03
Re: Password Salts - by ReneG - 26.06.2013, 17:07
Re: Password Salts - by MP2 - 26.06.2013, 17:25
Re: Password Salts - by iLinx - 26.06.2013, 19:15
Re: Password Salts - by Edvin - 27.06.2013, 07:09
Re: Password Salts - by Kreatyve - 27.06.2013, 08:03
Re: Password Salts - by MP2 - 27.06.2013, 10:53

Forum Jump:


Users browsing this thread: 1 Guest(s)