Anonymous Coward
Anonymous Coward

It depends. I've seen many authentication schemes where the salt is a single global constant. Sometimes the hash is truncated so that UID + hash is a tidy 64 bit int. It would take 10^19 guesses so it's secure, right? And it's not possible to re-encrypt because there are external APIs that use only the 64 bits to keep the password safe.

<sobbing uncontrollably>

