|
|
|
|
|
by daeken
5227 days ago
|
|
A single round of a hash -- salted or not -- is simply broken in 2012. When you can rent time on a bunch of GPUs on EC2 for effectively nothing, breaking the vast majority of hashes takes no work at all. PBKDF2 with a large number of rounds (10000 recommended), bcrypt, or scrypt are a requirement IMO. |
|
I'm wondering what sort of time frame you'd be looking at for a single round password, i.e; md5(salt.cleartext)