Add a column named 'salt' to USER, then the PASS column=PASSWORD(salt+'text');
Add a column named 'salt' to USER, then the PASS column=PASSWORD(salt+'text');
http://paulbuchheit.blogspot.com/2007/09/quick-read-this-if-...
SALT column = salt
Is the way used in most distributable web applications.
PASS column = HMAC(plaintext_pass, salt)
I might be wrong? As I understand it there are issues with MD5(MD5(password) + salt) that HMAC avoids. I'm still not 100% sure I understand the difference, but I think that is what the wikipedia article on HMAC is saying: http://en.wikipedia.org/wiki/HMAC#Design_principles
Dunno if it helps anything when it comes to salting. Anyone else who knows?
If the attacker was motivated to have Jeff Atwood's password, he could have grabbed the salted hash and used a password cracker against it. We're talking a single password for a high profile user, so why not spend a few hours of CPU time on it?
Only an adequate password hashing algorithm (ie, SLOW) would have really prevented this.
Use a different hashing function, probably bcrypt. (Note to self: go back and check some of my old code that did/does exactly what you describe...doh!)