would it be possible to thwart all possible password-cracking attacks by increasing the salt length to something large, like 64 bits? if not, which attacks are still likely to be effective?