3 ms·
Like protecting your business with an industrial grade door locks on a building made of hay. Just a whole lot of cheating going on over there, ouch. edit: I do
by tempVariable 11y ago
Like protecting your business with an industrial grade door locks on a building made of hay. Just a whole lot of cheating going on over there, ouch.
edit: I don't know if this came up before, but based on how they stupidly tried to cache the login session tokens with md5, instead of running through the 12 work factor bcrypt, I can assume that they saw this as a bottleneck.
Instead of dropping the work factor or doing this caching baloney, could a service be made that runs on extravagantly fast hardware, which provides an API for strong, high work factor bcrypt, pbkdf2 based authentication.
I can assume that at around 10 rounds, each attempt takes about 50 - 100 millis
Thoughts ?
- stan_rogers 11y agoThe "remember me" token doesn't need to contain or be derived from any meaningful data at all; it merely needs to be unique to the user so you can associate it with the user, and should be both unpredictable and frequently changed/regenerated. It's just a more persistent version of the session ID you'd be using in any case even if the "remember me" option wasn't selected.