Relevant XKCD: http://xkcd.com/1286/
Relevant XKCD: http://xkcd.com/1286/
Salts were critical from 1990s to around 2010, at which point they became mostly irrelevant for cracking accounts because of the increasingly parallel processing power that has exceeded the storage capacity of rainbow tables.
scrypt/bcrypt do the right thing, regardless, and generate unique password hash for the same plaintext, so if you use them you are covered both ways.
I found this statement confusing so I looked a PHP's documentation. http://php.net/manual/en/function.password-hash.php
Bcrypt does use a salt to create unique hashes for the same plaintext, it's just that the function is written so that a random salt is created and stored for you, you don't have to provide a salt along with the plaintext.
Other implementations may not work quite this way.
> scrypt/bcrypt do the right thing, regardless, and generate unique password hash for the same plaintext
Didn't know that. Thanks for pointing it out.