Earlier quoted context omitted.
Phishing the password from one user and recovering the salt shouldn't be useful in the first place. The parent example was only meant to show how difficult it is to recover a salt even with multiple examples of its use, not to give a real life example of password hash use. (Which was my point) That said, I don't know how you would obtain a list of hashed passwords without also getting the associated list of salts (wo…
Having the exact salt in the same database as the user data defeats the purpose of the salt. Normally you have a global salt, somewhere in your source-code, which you combine with the per-user generated salt. It also doesn't have to be something obvious in the database (like a column named user_salt :)), you could just use something like HMAC_MD5(global_salt, email + username + joined_date) for each user. Of course,…
but yes, a hashed (global + immutable-user-specific) combination seems to be best practice.