28 ms·
The breach notice indicates that hashed passwords were compromised but doesn't mention whether a salt was used when computing the hashes. Use of a salt makes a
by urlgrey 8y ago
The breach notice indicates that hashed passwords were compromised but doesn't mention whether a salt was used when computing the hashes.
Use of a salt makes all the difference, guarding against the use of rainbow tables to look up precomputed hashes of common passwords.
- mfonda 8y ago> The affected information included usernames, email addresses, and hashed passwords - the majority with the hashing function called bcrypt used to secure passwords. If they're using bcrypt, then they're using salts since salts are built in to bcrypt.