基于比特币课程Hash Hiding属性:哈希前拼接随机串'r'的原因探究
r to Input x Before Hashing? Great question! Let's break down the key reasons for this practice, especially tied to the "Hiding" property of cryptographic hash functions like those used in Bitcoin:
Thwart enumeration of high-probability inputs
Your initial guess is spot-on. Ifxis a low-entropy value (like a common password, short PIN, or frequently used string), attackers can easily precompute hashes for all likelyxvalues and compare them against the target hash to reverse-engineer the input. By appending a randomr, the actual input to the hash becomesr||x(the concatenation ofrandx). Even if two users have the samex, their uniquervalues will produce completely different hashes—making it impossible for attackers to use precomputed lists of commonxhashes to match the output.Neutralize rainbow table attacks
Rainbow tables are massive precomputed databases mapping common inputs to their hashes, designed to speed up reverse hash lookups. Adding a randomrrenders these tables useless. Sinceris unpredictable and high-entropy, the number of possibler||xcombinations is astronomically large—attackers can't possibly precompute hashes for every potentialrandxpair.Strengthen the core "Hiding" property
The Hiding property requires that given a hash output, it's computationally infeasible to determine the original input. Whenxhas low entropy (limited possible values), direct hashing fails this property because brute-forcingxis easy. By combiningxwith a high-entropy randomr, the total entropy of the input skyrockets. Even if an attacker guesses a possiblex, they'd also need to guess the exactrto verify their guess—and the randomness ofrmakes this computationally unfeasible for large enoughrsizes.
In cryptography, this random r is often called a salt, and it's a standard technique used in password storage, blind signatures (a concept relevant to Bitcoin's privacy features), and any scenario where we need to protect the privacy of low-entropy inputs.
内容的提问来源于stack exchange,提问作者rahs

