Salting: Is it reasonable to use the user name?

前端 未结 6 1912
礼貌的吻别 2021-02-20 16:53

I am debating using user-names as a means to salt passwords, instead of storing a random string along with the names. My justification is that the purpose of the salt is to prev

  •  刺人心
    刺人心 (楼主)
    2021-02-20 17:35

    You'll run into problems, when the username changes (if it can be changed). There's no way you can update the hashed password, because you don't store the unsalted, unhashed password.
