3 ms·
The proposals I've see have always had the initial scrypt be done on the server. The DOS risk on registration can be mitigated more easily than the login one.
by timv 11y ago
The proposals I've see have always had the initial scrypt be done on the server.
The DOS risk on registration can be mitigated more easily than the login one. e.g. Rate limiting new registrations will often be more palatable than limiting logins, or you can require "email validation" before you set the first password. And, not every application allows self registration.