Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My post was meant as a reply to the comment by psycr and I just moved it there.

My - and a very often valid - assumption is, that unique per user salts a stored together with the username and hash. Distributing this information across different systems will make it harder for attackers but such schemes are not very common. There is also the risk that the weakness that enables an attacker to compromise one part of the information will also enable them to compromise the other part(s). Therefore it is probably a good idea to use systems as different as possible to store the different parts, for example two different database systems from different vendors.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: