View Single Post
Old 10-04-2007, 09:36 PM   #7 (permalink)
drego
Upright
 
Location: WA......somewhere....I hope......
I agree that the salt should be different for each password. Dilberts spot on in that fact.

While we're sharing our schemas, the one that I'm currently a fan of is first i append a random salt to the password so we have <salt><password> string. From there I do a quick encryption of the string (Rijndael, static key / IV) and then hash it (SHA256).

The overhead isn't to bad at all, but I have not tested it with say....10000 simultaneous logins or anything.
__________________
There is no such thing as "Bug Free" software....there is only software with an acceptable (and documented) level of failure.

Hack the Planet!!!!
drego is offline  
 

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62