3 ms·
I agree, but it's actually hard not to nerf scrypt, since it's time-cost and memory-cost are tied together. I'm not sure if they could have increased the memor
by warbiscuit 10y ago
I agree, but it's actually hard not to nerf scrypt, since it's time-cost and memory-cost are tied together. I'm not sure if they could have increased the memory cost sufficiently for their purposes, without making the time cost prohibitively high.
That's one of the things argon2 (https://github.com/P-H-C/phc-winner-argon2 https://github.com/P-H-C/phc-winner-argon2) is trying to fix, though I don't think any cryptocurrencies are using it yet (which is reasonable, it's just too young)
- bqe 10y agoThis paper also describes an attack on Argon2, which lowers the amount of memory required by an attacker.