Could someone please help me understand how salting works?
So far I understand the following:
- Validate password
- Generate a random string
- Hash the password and the random string and concat them, then store them in the password field...
How do we store the salt, or know what it is when a user logs in? Do we store it in its own field? If we don't, how does the application figure out what the salt is? And if we do store it, doesn't it defeat the whole purpose?