To Salt or Not To Salt? — Salting is not the only answer to securing passwords

Prof Bill Buchanan OBE FRSE
Published in
9 min readAug 9, 2018


It was recently released that LinkedIn failed to salt its passwords in the 2012 hack, and while salting would have increased the time it takes to crack a salted hash, it is merely a bump in the road if users use passwords such as “123456”.

Why? Because the salt is typically stored with the hashed password, so if the user selects…



Prof Bill Buchanan OBE FRSE

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.