4 ms·
>But: all the password hashes are fine, including the ones that aren't space-hard. Not quite sure this is true: the Alwen-Blocki attack at CRYPTO this year (an
by swordswinger12 10y ago
>But: all the password hashes are fine, including the ones that aren't space-hard.
Not quite sure this is true: the Alwen-Blocki attack at CRYPTO this year (and some other nice recent work) demonstrated that there are some subtleties in this area that we don't fully understand yet.
- tptacek 10y agoReducing the memory requirements of a space-hard password hash is important in theoretical terms, and perhaps for systems built around the hardness of a space-hard KDF as, for instance, a proof of work. But it's of virtually no bearing whatsoever to business applications that store passwords. Your space-hard password hash is less space-hard than you hoped it would be. Oh well. The low-hanging fruit is using salted SHA hashes.