Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Only if the salt is kept secret. There also needs to be a different salt value per ip, obviously. But given those conditions, it works.

Of course, it would be just as simple to use the salt as-is, in that case, since you have to look it up anyway.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: