A salt is used because without it you can authenticate simply by using a replay attack