Re: OT: password encryption (salt theory)

Поиск
Список
Период
Сортировка
От Tim Ellis
Тема Re: OT: password encryption (salt theory)
Дата
Msg-id 20020822112945.3d37c2ff.Tim.Ellis@gamet.com
обсуждение исходный текст
Ответ на Re: OT: password encryption (salt theory)  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-admin
> > Can anyone explain to me why a salt is really a good idea
>
> I believe the original purpose was to make it less obvious whether two
> Unix users had the same password.

Ah, plus, as was also pointed out, the attacker cannot precompute a
dictionary attack -- she must do a dictionary attack PER PASSWORD, not per
password file.

This all makes sense. Conclusion: Salt is good. Random salt is best. Any
salt is better than no salt. Thanks for clarifying it, everyone.

--
Tim Ellis
Senior Database Architect
Gamet, Inc.

В списке pgsql-admin по дате отправления:

Предыдущее
От: Kevin Brannen
Дата:
Сообщение: Re: mysqldiff-like utility for PG?
Следующее
От: Robert Treat
Дата:
Сообщение: Re: mysqldiff-like utility for PG?