|
|
|
|
|
by tptacek
3184 days ago
|
|
The most popular post that ever ran on Matasano's security blog was the one where I encouraged people to migrate to bcrypt. In 2007. Bcrypt, of course, is much older; Niels and David invented it as the standard password format for OpenBSD back in 1999 --- and bcrypt was a response to FreeBSD's iterated salted hash format, which also had a work factor, and is years older still. Today, in 2017, bcrypt remains a sound recommendation. You can do better, but for password databases on websites, not materially better. Salted SHA-1 hashes (salted SHA-anything hashes) were malpractice in 2012. |
|
Do you mean using scrypt? What do you mean by materially better?