pepper.
secret added to an input such as a password prior to being hashed with a cryptographic hash function and not stored alongside the hashed output (unlike a salt)
The journal
Open the journal →The conversation starts in the journal — be the first to post.
About pepper
In cryptography, a pepper is a secret added to an input such as a password during hashing with a cryptographic hash function. This value differs from a salt in that it is not stored alongside a password hash, but rather the pepper is kept separate using another mechanism, such as a Hardware Security Module. Note that the National Institute of Standards and Technology refers to this value as a secret key rather than a pepper. A pepper is similar in concept to a salt or an encryption key. It is like a salt in that it is a randomized value that is added to a password hash, and it is similar to an encryption key in that it should be kept secret.
Everything about pepper →