Password Security: Salting vs Hashing
Which of the following best describes the process of adding a secret value to extend the length of stored passwords?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the specific definition of salting versus general hashing, highlighting that salting extends the input data to defeat precomputed lookup tables.
Salting is the cryptographic technique used to add a random secret value to passwords before hashing. This process prevents rainbow table attacks by ensuring identical passwords produce different hashes.
Candidates often select 'Hashing' because it is the primary mechanism for storing passwords, but they miss the specific detail about adding a secret value to extend length or uniqueness.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Correct answer: C — Salting involves appending a unique, random string (the salt) to a password before it is processed by a hash function. This ensures that even if two users have the same password, their stored hashes will differ significantly, effectively extending the complexity and defeating precomputed dictionary attacks.Why the Other Options Are Wrong
Hashing (A) is the algorithmic process of converting data into a fixed-size string, but it does not inherently involve adding an external secret value. Perfect Forward Secrecy (D) is a property of key exchange protocols in secure communications, unrelated to password storage. Quantum communications (B) refers to transmission methods using quantum mechanics and is irrelevant to this context.Community Comment Notes
Community consensus strongly supports Salting as the correct term for adding random data to passwords. As salah112 noted, "The salt is combined with the user's password before hashing... making it more difficult for attackers to use precomputed tables." Other users confirmed that "Add = Salting," reinforcing the direct link between the action described and the terminology.Exam Strategy
Focus on distinguishing between the mechanism (hashing) and the enhancement (salting). When questions mention 'random value,' 'unique per user,' or 'extending password length,' think immediately of salting to prevent rainbow table attacks.
Frequently Asked Questions
Why isn't Hashing the correct answer?
Hashing is the transformation algorithm. Salting is the specific act of adding random data to the input before hashing to increase security against precomputed attacks.
How does Salting prevent Rainbow Tables?
Rainbow tables rely on precomputed hashes of common passwords. Since each salted password has a unique random prefix/suffix, the resulting hash is unique, rendering generic rainbow tables useless.