Is it appropriate to use an HMAC and pepper to hash input from a limited domain

Viewed 198

I have a payload p that comes from a limited domain. I want to hash p to produce a unique signature and store it. This will allow detection of duplicate ps that I might receive later.

Since p comes from a small domain, and is somewhat sensitive, I plan to use a pepper when hashing to prevent against rainbow table attacks (if there are better approaches to deal with limited domain data, I would welcome recommendations)

When hashing p, is it preferred to compute the hash via an HMAC algorithm. Per this post, HMAC-SHA256(pepper, p) seems like it's preferrable to SHA256(concat(p, pepper)).

0 Answers
Related