π Password Salting vs Peppering: A CISSP Quick Guide
Passwords should never be stored in plaintext. They should be protected using a suitable password-hashing algorithm.
Two important concepts are salting and peppering.
π§ What is Password Salting?
A salt is a random value combined with a password before password hashing.
Password + Salt
β
βΌ
Password Hash
A salt is normally unique for each password.
Without salt:
password123 β Hash β ABC123
password123 β Hash β ABC123
With different salts:
password123 + X7k9 β Hash β 111AAA
password123 + P2m4 β Hash β 999BBB
So, the same password produces different hashes.
Key purpose: Salts make precomputed/rainbow-table attacks ineffective and prevent identical passwords from having identical hashes.
Important: A salt is not secret and is normally stored with the password hash.
πΆοΈ What is Password Peppering?
A pepper is a secret value used as an additional input to password protection.
Password + Salt + Pepper
β
βΌ
Password Protection
β
βΌ
Hash
Unlike a salt, the pepper is kept secret and stored separately from the password database, such as in a secure secret-management system.
Password Database
ββββββββββββββββββββββββ
β Username β
β Salt β
β Password Hash β
ββββββββββββββββββββββββ
Separate Secret Store
ββββββββββββββββββββββββ
β Pepper β
ββββββββββββββββββββββββ
If an attacker steals only the password database, they do not have the pepper, adding another layer of protection against offline password cracking.
βοΈ Salt vs Pepper
| π§ Salt | πΆοΈ Pepper | |
|---|---|---|
| Purpose | Make password hashes unique | Add a secret protection factor |
| Unique per password? | Yes, normally | Usually not |
| Secret? | β No | β Yes |
| Stored with hash? | Yes | No |
| Main benefit | Defeats precomputed/rainbow-table attacks | Adds protection if the password database is compromised |
π― CISSP Memory Trick
π§ SALT = Random + Unique + Not Secret
β Stored with the hash
πΆοΈ PEPPER = Secret + Separate
β NOT stored with the hash
Salt makes hashes different.
Pepper adds a secret the attacker should not have.
CISSP Remember
Salt β encryption
Pepper β encryption
Both are techniques used to strengthen password protection, not to encrypt passwords.
Also, avoid using fast general-purpose hashes such as MD5 or SHA-256 directly for password storage. Passwords should use a purpose-built password hashing/KDF approach.

