Salt (Password)
A unique, random value mixed into a password before hashing so identical passwords produce different hashes, defeating precomputed rainbow tables and cross-account collisions.
A salt is a per-password random value (typically 16+ bytes) concatenated with the password before it hits the hash function. Two users with the same password get two completely different stored hashes, which kills the economics of rainbow tables and prevents an attacker from spotting password reuse across accounts in one stolen database. Salts are not secret; they are stored alongside the hash so the same derivation can be reproduced at verification time. Modern password hashing functions (Argon2, bcrypt, scrypt, PBKDF2) all take a salt parameter and bake it into their standard encoded output, so the application rarely has to handle salts directly.
Reference
Related terms
See also
Referenced on
- APR1 Generator, Free Online, Apache $apr1$ MD5 Hashes
- Argon2 Hash Generator, Free Online, OWASP Recommended
- Bcrypt Generator & Verifier, Free Online, Browser-Only
- Django Password Hash Generator, Free Online, PBKDF2 SHA-256
- DNS Zone Walking at the TLD Level: How Attackers Discover Every Domain in a TLD
- DNS Zone Walking for Subdomain Enumeration: How NSEC Exposes Your Subdomains
- Drupal Password Hash Generator, Free Online, $S$ Format
- HTPasswd Generator Free Online, bcrypt, APR1, SHA, crypt
- Linux Shadow Hash Generator, Free Online, SHA-512 $6$
- MySQL Password Hash Generator Free Online, PASSWORD()
- NTLM Hash Generator, Free Online, Windows Format
- PBKDF2 Generator, Free Online, Custom Iterations
- PostgreSQL Password Hash Generator, Free Online, SCRAM
- What Is DNSSEC and Why Should You Enable It?
- WordPress Password Hash Generator, Free Online (phpass, Bcrypt)