5 ms·
You might be interested in why I feel this way. I actually have a pretty strong anti-bcrypt bent. Not to just point back to my blog again, but I've written tw
by himalayanyeeti 8y ago
You might be interested in why I feel this way. I actually have a pretty strong anti-bcrypt bent. Not to just point back to my blog again, but I've written two anti-bcrypt posts which may be viewed here:
https://blog.benpri.me/blog/2019/01/13/why-you-shouldnt-be-using-bcrypt-and-scrypt/ https://blog.benpri.me/blog/2019/01/13/why-you-shouldnt-be-u...
and here:
https://blog.benpri.me/blog/2019/03/02/reactive-hashing/ https://blog.benpri.me/blog/2019/03/02/reactive-hashing/
- vince14 8y agoYour first post is very dishonest and misleading. In conclusion you are comparing long vs short passwords but attach the hash algorithms to them to fit your narrative. Both points in conclusion are wrong and as noted in the comments: you would run a dictionary attack on your chosen longer password. Which is a bit ironic because this "lulls you into a false sense of security".
- Tade0 8y agoI read the first article. Passphrases give us the ability to easily remember high entropy password values. Passphrases are not high entropy once you take into account that they're words in a specific language.
- isostatic 8y agoDepends how you pick them. If you genuinely do grep "^[a-z]*$" /usr/share/dict/words|shuf -n 4 Then on my computer you're looking at 15638751293495759880 combinations, or about 2^64. Pick them from your own day to day vocab and you're more likely in the 2^32 range.
- mgkimsal 8y agocolor me stupid but I didn't understand "You should not be using Bcrypt. You should be using passphrases." These seem orthogonal to each other. How would you store the 'passphrases'? in plaintext? or hashed? if hashed, what hashing algorithm? Why not bcrypted passphrases?