Which of the following best explains why 'Rainbow Tables' are less effective against modern systems that implement salted hashes?
Rainbow tables rely on the fact that a specific password always results in the same hash. By appending a salt, the hash calculation changes for each user. An attacker would have to compute a unique table for every single salt, destroying the efficiency of precomputation.
Why this answer
Rainbow tables are precomputed tables of hashes for all possible plaintext passwords within a specific character set. By adding a random, per-user salt before hashing, the final hash becomes dependent on both the password and the salt. This means an attacker would need to build a new rainbow table for every unique salt, rendering precomputed tables computationally useless.
Exam trap
Candidates often incorrectly assume salts make hashes impossible to crack, rather than understanding that salts specifically break the efficiency of precomputed rainbow tables.