• The salt adds nothing

    It prevents cross-service re-use, should the original password hash be obtained (if other services used the same system).

    Example (MD5 in b64 used for simplicity): Same password is used on website1 and website2. The password is password.
    password produces KGdV+tBIacpSMyCszg3GpA== which can be used for both websites.
    Now, if website1 adds sbo2 as salt, and website2 addsx3e5, you get:
    passwordsbo2 -> d0bd511zpYqG3//3vLGYRQ==
    passwordx3e5 -> 788BnQKx7B2KOSju2jviiQ==

    So if you are on a corporate network that does MITM (you had to add their root cert) for monitoring, they’ll only see a hash for each website separately, without being able to re-use it.
    Though that’s quite a bit of an edge case, and assumes no client modification or other monitoring.

    • pet the cat, walk the dog@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      23 hours ago

      True, I got engrossed in thinking through your proposal and forgotten about the original intent of a salt. Happens to me from time to time, particularly with security topics for some reason.