Salt and hashing, why not use username?
问题 I must confess to being largely ignorant on most of the high-tech security issues relevant for web applications, but there is one thing I at least thought I could ask because it is a direct question with (hopefully) a concrete answer. Take this website: http://www.15seconds.com/issue/000217.htm It shows a bit down that they store the salt value in the table, I understand the principles and the math behind using a salt, but I'm wondering this: Why did they not just use the username as a salt