3 ms·
You're asking about the relative merit of two hash functions, one of which allows your attacker to test a candidate password in 1 millisecond, the other of whic
by codahale 17y ago
You're asking about the relative merit of two hash functions, one of which allows your attacker to test a candidate password in 1 millisecond, the other of which allows the same in less than 1 nanosecond. Using the latter provides your attacker with a 1,000,000x productivity boost. Personally, I'm not that generous.
As far as CPU exhaustion, there are some huge sites which use bcrypt (like, in the top 10)[1]. It is not a problem, provided you choose your work factor carefully.
As far as complex passwords, use them. Try to get your users to use them. But it's an orthogonal concern: your attacker will still be able to work their way through the gigantic keyspace of your monster passwords at 1,000,000x the rate of what they could do if you'd have used bcrypt.
[1] Just looked this up. Not the top 10, but the top 15 for sure.