On Tue, Aug 6, 2013 at 1:04 PM, Michael Peppard <mpeppard (at) impole (dot) com [email concealed]> wrote:
> "Finally, given salt predominantly in use in modern password hash
> schemes, pen testing in realistic modern conditions, are rainbow
> tables still of value?"
> The sole purpose of salt is to make rainbow tables extinct. It has no
> other value ...
Salts also ensure that two users with the same password have different
digested password entries in the database.

It was recently proven that salt is a good thing. "Multi-Instance
Security and its Application to Password-Based Cryptography,"



