Skip to main content

Command Palette

Search for a command to run...

πŸ” Password Salting vs Peppering: A CISSP Quick Guide

Updated
β€’3 min readβ€’View as Markdown
S
I like breaking things that are supposed to be secure. When I’m not hunting vulnerabilities, I’m exploring systems, architectures, and the assumptions behind them.

Passwords should never be stored in plaintext. They should be protected using a suitable password-hashing algorithm.

Two important concepts are salting and peppering.

πŸ§‚ What is Password Salting?

A salt is a random value combined with a password before password hashing.

Password + Salt
      β”‚
      β–Ό
 Password Hash

A salt is normally unique for each password.

Without salt:

password123 β†’ Hash β†’ ABC123
password123 β†’ Hash β†’ ABC123

With different salts:

password123 + X7k9 β†’ Hash β†’ 111AAA
password123 + P2m4 β†’ Hash β†’ 999BBB

So, the same password produces different hashes.

Key purpose: Salts make precomputed/rainbow-table attacks ineffective and prevent identical passwords from having identical hashes.

Important: A salt is not secret and is normally stored with the password hash.


🌢️ What is Password Peppering?

A pepper is a secret value used as an additional input to password protection.

Password + Salt + Pepper
          β”‚
          β–Ό
 Password Protection
          β”‚
          β–Ό
         Hash

Unlike a salt, the pepper is kept secret and stored separately from the password database, such as in a secure secret-management system.

Password Database
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Username             β”‚
β”‚ Salt                 β”‚
β”‚ Password Hash        β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Separate Secret Store
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Pepper               β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

If an attacker steals only the password database, they do not have the pepper, adding another layer of protection against offline password cracking.


βš–οΈ Salt vs Pepper

πŸ§‚ Salt 🌢️ Pepper
Purpose Make password hashes unique Add a secret protection factor
Unique per password? Yes, normally Usually not
Secret? ❌ No βœ… Yes
Stored with hash? Yes No
Main benefit Defeats precomputed/rainbow-table attacks Adds protection if the password database is compromised

🎯 CISSP Memory Trick

πŸ§‚ SALT  = Random + Unique + Not Secret
           β†’ Stored with the hash

🌢️ PEPPER = Secret + Separate
           β†’ NOT stored with the hash

Salt makes hashes different.
Pepper adds a secret the attacker should not have.

CISSP Remember

Salt β‰  encryption
Pepper β‰  encryption

Both are techniques used to strengthen password protection, not to encrypt passwords.

Also, avoid using fast general-purpose hashes such as MD5 or SHA-256 directly for password storage. Passwords should use a purpose-built password hashing/KDF approach.