Hacker News new | ask | show | jobs
by bga 3205 days ago
If you're just hashing with SHA2 and a salt, an attacker with a run-of-the-mill GPU could crack any given hashing quite quickly. It might still take quite a bit of time to get all 143 million, but that's fine. Sell off the score in blocks of 10,000 and let the customer know they have to reverse the hashes themselves.

BCrypt with lots of rounds would be best.

1 comments

Yes. You're correct of course. We should be treating these like passwords, except that they can't be rotated...