|
|
|
|
|
by tptacek
4678 days ago
|
|
bcrypt is already randomized, as is every other modern KDF. There is no such thing as a bcrypt rainbow table. Rainbow tables have never really mattered. Stop thinking about rainbow tables. You need to be using real KDFs to store passwords. Salted hashes are not real KDFs. |
|
When it comes to picking passwords that humans can remember, what's your opinion on Diceware? Do five or six word passwords still stand up with the increases in computational power? http://world.std.com/~reinhold/diceware.html