Salting: Is it reasonable to use the user name?

前端 未结 6 1912
礼貌的吻别
礼貌的吻别 2021-02-20 16:53

I am debating using user-names as a means to salt passwords, instead of storing a random string along with the names. My justification is that the purpose of the salt is to prev

6条回答
  •  刺人心
    刺人心 (楼主)
    2021-02-20 17:35

    You'll run into problems, when the username changes (if it can be changed). There's no way you can update the hashed password, because you don't store the unsalted, unhashed password.

提交回复
热议问题