3 ms·
If you were already using bcrypt (or any "slow hash algorithm"), double-hashing may be very slow.
by esnard 11y ago
If you were already using bcrypt (or any "slow hash algorithm"), double-hashing may be very slow.
- msbarnett 11y agoYou only have to do it when you in-place upgrade the entire table, and once when the user initially logs in after that. Once the user has logged in successfully, you can replace new_hash(old_hash(password)) with simply new_hash(password). This is less useful for optimistic upgrades like bcrypt->argon2i, but is absolutely critical if you find yourself taking over responsibility for a database that has a password column full of, say, MD5s. Waiting for each and every user to log in to upgrade those vulnerable hashes is suicidal.