3 ms·
If you have ten people logging in per second, you've got to have more than one server. Distribute the login requests. And if it really kills you to make it tak
by Xk 16y ago
If you have ten people logging in per second, you've got to have more than one server. Distribute the login requests.
And if it really kills you to make it take a full second, then make it take 1/10th of a second: there, now your hashing is faster than the time it takes to dynamically generate a page.
People really need to learn that security doesn't come free, and some times you just need to bite down and say "You know what? I never plan on getting broken into, but just in case I do I'll take the tenth of a second extra computation in exchange for doing the right thing."