Likely the most painful password hashing discussion you'll ever read 12 years ago
Could a hacker learn the hash key and salting by opening a bunch of accounts on the site before stealing the database, then comparing his known passwords with the hashed values?