Let's add some basil to our password hashing, I'm thinking username with an extra something generated that is stored in the user table. https://crackstation.net/hashing-security.htm#attacks