Ninjastic
Home
Search
Users
Boards
Addresses
Ctrl + K
Toggle theme
Open menu
Post
Edited versions
Quotes to this post
Post
948061
Topic
84992
Board
Services
Re: SMF modification needed -- upgrade password hash security -- 40 BTC
by
publio
on
08/06/2012, 00:08:47 UTC
It's considered best practice to use CSPRNGs for any cryptography, including salts. Predictable salts may offer protection against rainbow tables.. Maybe it protects against "theoretical attacks"?
Take a look at this page:
http://books.google.com/books?id=QJNoykS0Tv4C&lpg=PT199&ots=JN9mj5AsnT&dq=salt+csprng&pg=PT199&redir_esc=y#v=onepage&q&f=false
It turns out that urandom is also cryptographically secure.
The php function, mt_rand(), for example, is not.