Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What's the OP is talking about is commonly called a 'pepper'. Some fixed secret in your application code that impacts the generated hash.

Since salts are random, and unique per password, you shouldn't be storing them in a config file.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: