Hacker News new | past | comments | ask | show | jobs | submit login

I use the hashed password as input in order to create short lived hashes for other purposes.

By changing the salt, you change the hashed password. So when the user changes their password it actually changes, and those other hashes change too.

If you kept the salt the same then if the user changes the password back to what it was nothing actually changes.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: