Advertisement:

Author Topic: Hash Salt and Username  (Read 912 times)

Offline Syard

  • Newbie
  • *
  • Posts: 1
Hash Salt and Username
« on: January 17, 2019, 05:37:11 AM »
Hey hey !

So I'm having a problem with paswords, I'd like to understand better what's going on with the hashing algorithm, from my research, it uses the username as a salt : is that the case for v1.1 ?
Why is there a "Salt" in my smf_members table if the salt used is the username ?

Thanks for your insight !
Syard

Offline Arantor

  • Resident Overthinker
  • SMF Friend
  • SMF Legend
  • *
  • Posts: 71,824
    • StoryBB/StoryBB on GitHub
Re: Hash Salt and Username
« Reply #1 on: January 17, 2019, 06:23:49 AM »
The salt is the username, that extra column is related to password reset and also used to identify if the user has come from SMF or a different platform via conversion (as SMF tried to let the user use their old password)
Don’t try to tell me that some power can corrupt a person. You haven’t had enough to know what it’s like.

No good deed goes unpunished / No act of charity goes unresented.