2 ms·
The best motivation I've heard is here: http://security.stackexchange.com/a/17088/77002 http://security.stackexchange.com/a/17088/77002 Essentially, blowfish (
by grangerg 10y ago
The best motivation I've heard is here: http://security.stackexchange.com/a/17088/77002 http://security.stackexchange.com/a/17088/77002
Essentially, blowfish (Bcrypt) doesn't appear to be FIPS-compliant, so if you have to be FIPS-compliant, you use PBKDF2.
And, considering the rest of the comments about why Bcrypt is preferred over PBKDF2, it appears it's all about how a GPU gives a significant speed-up for PBKDF2 but not Bcrypt. But now there are FPGAs that significantly speed up Bcrypt in similar fashion, so it could all be a wash depending on who you talk to.