Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

An attacker can pre-compute hashes of common passwords for common settings of bcrypt/scrypt. With a salt, they have to start from scratch every time.


bcrypt and scrypt are always salted (it's part of their algorithms - there is not such thing as unsalted bcrypt/scrypt)


No. No, they cannot.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: