Salts make identical passwords look different
Without a salt, two people who chose the same password have identical entries in the database.
An attacker can see at a glance which accounts share a password, and cracking one cracks all of them at once. A unique salt per account makes those entries look completely different, so every password has to be attacked separately. It does not make any single password stronger. It removes the economy of scale, which is what makes cracking a stolen database quick.
More on Passwords and secrets
- Password length beats decorative complexityAdd wheels, not squiggles
- Forced rotation can create predictable passwordsOnly one character moves
- Every secret copy creates another secret to protectEvery copy needs its own guard
- Secrets in source control have a long memoryThe deletion is just another commit
- Environment variables are not secret vaultsA label on the outside of the bag
- Temporary credentials shrink the theft windowSame theft, different window
