4 ms·
It's PBKDF2 with SHA1, 4096 iterations and 32 bytes of output. That's relatively weak, and thanks to the defective structure of PBKDF2, an attacker will parall
by ctz 10y ago
It's PBKDF2 with SHA1, 4096 iterations and 32 bytes of output. That's relatively weak, and thanks to the defective structure of PBKDF2, an attacker will parallelise each output block.
- lucb1e 10y agoRelatively weak indeed, as expected from a standard that wasn't made recently. Still, about 4000 times slower than a single hash, which adds about as much as adding two characters to the password if I'm not mistaken (assuming a random password, which they usually aren't, which gives roughly 94*94=9k extra possibilities -- a bit more than 4k but the same order of magnitude).