# 🔐 Password Salting vs Peppering: A CISSP Quick Guide

Passwords should **never be stored in plaintext**. They should be protected using a suitable **password-hashing algorithm**.

Two important concepts are **salting** and **peppering**.

## 🧂 What is Password Salting?

A **salt** is a **random value combined with a password before password hashing**.

```text
Password + Salt
      │
      ▼
 Password Hash
```

A salt is normally **unique for each password**.

Without salt:

```text
password123 → Hash → ABC123
password123 → Hash → ABC123
```

With different salts:

```text
password123 + X7k9 → Hash → 111AAA
password123 + P2m4 → Hash → 999BBB
```

So, the same password produces different hashes.

**Key purpose:** Salts make **precomputed/rainbow-table attacks** ineffective and prevent identical passwords from having identical hashes.

**Important:** A salt is **not secret** and is normally stored with the password hash.

* * *

## 🌶️ What is Password Peppering?

A **pepper** is a **secret value used as an additional input to password protection**.

```text
Password + Salt + Pepper
          │
          ▼
 Password Protection
          │
          ▼
         Hash
```

Unlike a salt, the pepper is **kept secret and stored separately** from the password database, such as in a secure secret-management system.

```text
Password Database
┌──────────────────────┐
│ Username             │
│ Salt                 │
│ Password Hash        │
└──────────────────────┘

Separate Secret Store
┌──────────────────────┐
│ Pepper               │
└──────────────────────┘
```

If an attacker steals only the password database, they **do not have the pepper**, adding another layer of protection against offline password cracking.

* * *

## ⚖️ Salt vs Pepper

|  | 🧂 **Salt** | 🌶️ **Pepper** |
| --- | --- | --- |
| **Purpose** | Make password hashes unique | Add a secret protection factor |
| **Unique per password?** | **Yes, normally** | Usually not |
| **Secret?** | ❌ No | ✅ Yes |
| **Stored with hash?** | **Yes** | **No** |
| **Main benefit** | Defeats precomputed/rainbow-table attacks | Adds protection if the password database is compromised |

* * *

## 🎯 CISSP Memory Trick

```text
🧂 SALT  = Random + Unique + Not Secret
           → Stored with the hash

🌶️ PEPPER = Secret + Separate
           → NOT stored with the hash
```

> **Salt makes hashes different.  
> Pepper adds a secret the attacker should not have.**

### CISSP Remember

**Salt ≠ encryption**  
**Pepper ≠ encryption**

Both are techniques used to strengthen **password protection**, not to encrypt passwords.

Also, avoid using fast general-purpose hashes such as **MD5 or SHA-256 directly for password storage**. Passwords should use a purpose-built password hashing/KDF approach.
