3 ms·
You'd want to distribute the load of your slow password-hashing functions across your application servers rather than centralizing it in your single database.
by danneu 9y ago
You'd want to distribute the load of your slow password-hashing functions across your application servers rather than centralizing it in your single database.
- icebraining 9y agoYou can have more than on database node as well.
- rpedela 9y agoPostgres bcrypt is wicked fast. You need some crazy load before it makes sense to move hashing out of the DB.
- Xylakant 9y agoIf your PW hashing function is wicked fast, you need to increase the work factor. The whole idea of a paw hash is to be comparatively slow, because that's one property that makes it harder to crack. Otherwise we could all go back to salted md5
- jeltz 9y agoPlease change to a higher factor. PostgreSQL's default is a bit outdated and too low for modern computers.