3 ms·
Imagine this Python code (I'm using SHA1 iterated multiple times, basically PBKDF2): import hashlib hashed = password for i in range(50000):
by miGlanz 16y ago
Imagine this Python code (I'm using SHA1 iterated multiple times, basically PBKDF2):
import hashlib
hashed = password
for i in range(50000):
hashed = hashlib.sha1(salt + hashed)
Provided we also store the number of iterations (along with the salt), and provided I didn't do anything stupid above, we could simply add more iterations after these 5 years and update hash and number of iterations field. Would it be a viable solution?
- tptacek 16y agoYes.
- miGlanz 16y agoSo the original question remains, is it possible with bcrypt?
- tptacek 16y agoI don't know, but Oliver Hunt suggested just validating the password on the next login and upgrading it on the fly, which, to be honest, is what I'd probably do.
- marcinw 16y agoimport bcrypt hashed = bcrypt.hashpw(password, bcrypt.gensalt(log_rounds=13)) Increasing log_rounds by one increases the work factor exponentially (2 * * log_rounds).
- csytan 16y agoI rigged up a small test on my Macbook. Do you think 50,000 iterations would be enough for a general website (such as HN)? import timeit t = timeit.Timer(stmt="""\ def test(pwd, n_iter): for i in range(n_iter): pwd = hashlib.sha1(pwd).hexdigest() test('hello', 50000) """, setup='import hashlib') print t.timeit(100) / 100 >>> 0.126629960537