Glossary Security

Salt

A salt is a unique random value added to a password before hashing, so that identical passwords produce different hashes.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

The salt is stored in the clear next to the hash. It defeats precomputed "rainbow tables" and means a thief must attack each password separately. Modern password hashes such as bcrypt and Argon2 generate and store the salt automatically. A salt is not a secret key, and it does not make a weak password strong.

Try these tools

See also

  • Glossary Hash
    A hash is the fixed-length fingerprint a hash function computes from any input; the same input always gives the same hash.
  • Glossary Brute-force attack
    A brute-force attack tries every possible password or key, or a huge list of likely ones, until one works.
  • Guide How Hashing Works
    What a hash function does, the avalanche effect shown with real SHA-256 output, which algorithms are still safe, HMAC.
AdSense Placeholder
Slot: footer_leaderboard