3 ms·
> After the first hash, it's just hashing a hash The recommended password hashing functions (PBKDF2, bcrypt, scrypt) actually use the provided password in each
by phlo 11y ago
> After the first hash, it's just hashing a hash
The recommended password hashing functions (PBKDF2, bcrypt, scrypt) actually use the provided password in each iterated round of the algorithm. The DoS vector Someon1234 mentioned is real and has previously affected Django[0] (and, I believe, others). In order to prevent it, you should either limit the maximum password length (256 characters seems sensible, as does Django's choice of 4096) or hash the password (to a known length) before passing it to the KDF.
[0] http://arstechnica.com/security/2013/09/long-passwords-are-good-but-too-much-length-can-be-bad-for-security/ http://arstechnica.com/security/2013/09/long-passwords-are-g...