Does salt need to be random to secure a password hash? private static byte[] HashPassword(string password) { using (var deriveBytes = new Rfc2898DeriveBytes(password, 10)) { byte[] salt = deriveBytes.Salt; byte[] key = deriveBytes.GetBytes(20); return salt.Concat(key).ToArray(); //Return Salt+Key } } var salt = //1st 10 bytes stored in the DB var key = //Next 20 bytes stored in the DB using (var deriveBytes = new Rfc2898DeriveBytes(password, salt)) { byte[] newKey = deriveBytes.GetBytes(20); if (newKey.SequenceEqual(key) == false) //Check if keys match { return "No Match"; } else { return "Passwords match"; }