On Apr 23, 2014, at 10:44 AM, [email protected] wrote:

> Hence why you'd "salt" it by adding some extra string to the password before 
> saving it.  Some on here have talked about random salts, but that gives me a 
> headache.  How would you keep track of the random salt?

You store it, believe it or not.

Read this article; the section on salting is good:
http://throwingfire.com/storing-passwords-securely/


-- Ed Leafe



--- StripMime Report -- processed MIME parts ---
multipart/signed
  text/plain (text body -- kept)
  application/pgp-signature
---

_______________________________________________
Post Messages to: [email protected]
Subscription Maintenance: http://mail.leafe.com/mailman/listinfo/profox
OT-free version of this list: http://mail.leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: 
http://leafe.com/archives/byMID/profox/[email protected]
** All postings, unless explicitly stated otherwise, are the opinions of the 
author, and do not constitute legal or medical advice. This statement is added 
to the messages for those lawyers who are too stupid to see the obvious.

Reply via email to