So a password with different salts will result in a different hashes. Therefore you have to know the salt in order to guess the password (for offline matching against a dataset of hashed passwords retrieved from a target site). Ideally, every password will have a different salt, and the dataset of salts is stored separately from the dataset of hashes.
Or am I missing something? (Genuine question, because this is not my area of expertise).
Ideally, every password will have a different salt,
More than ideally, the only way it makes any sense at all is if they are different.
As an example:
User: bob password: password1 password hash: 12345
User: sue password: password1 password hash: 12345
with salt that is the same for all users:
User: bob password: password1 salt: 7 password hash: 22345
User: sue password: password1 salt: 7 password hash: 22345
with salt that is different per user
User: bob password: password1 salt: 7 password hash: 22345
User: sue password: password1 salt: 8 password hash: 32345
Per user salt means that an attacker who has stolen the password db can't crack one password and unlock 100 accounts because they all have the same password hash. That is the only point of a salt it serves no other purpose.
I wouldn't say no other purpose. A single common salt can at least protect you from the guy who has a pre-computed lookup table of dictionary words hashed with a standard, unsalted function. (That is, it prevents a zero-computation attack.) Admittedly that doesn't gain you much these days, but it's not "zero benefit".
http://www.securityfocus.com/blogs/262
To quote, emphasis his: Using raw hash functions to authenticate passwords is as naive as using unsalted hash functions. Don’t.
[1] See towards the end of the very comprehensive first answer. http://security.stackexchange.com/questions/211/how-to-secur...
Then go back, read the rest of it :)
i think the answer from rory mcclune puts it well: "Another add-on I've seen to this is to also add in what was called a pepper value. This was just another random string but was the same for all users and stored with the application code as opposed to in the database. the theory here is that in some circumstances the database may be compromised but the application code is not, and in those cases this could improve the security. It does, however, introduce problems if there are multiple applications using the same password database."