Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

On step 3, where you say "scrypt(s'i, md5(si, password))", don't you actually need "scrypt(s'i, md5(s0, password))", where s0 is the original salt? In other words, you still need to know the original salt you were using to successfully migrate.

Therefore, if you are storing the per-user salt as the first bytes in the hashed password field, then you have to be careful when you "throw away the old weak hash hi and forget it ever existed."



The original salt is s_i which you do need to keep around. The new salt is s^'_i.


Ah. my mistake. I completely missed the "'" as I was reading it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: