3 ms·
I do not see how this is relevant to what I said.
by dependenttypes 6y ago
I do not see how this is relevant to what I said.
- willcipriano 6y agoThe method you purpose is less secure as humans often use low entropy passwords even when you ask them not to. If you are building a system only for humans that use high entropy passwords (are you really willing to bet the farm on that just to save a couple clock cycles) or other machines it might work but I also see no benefit to that approach so you might as well just bcrypt it and call it a day anyway.
- dependenttypes 6y agoI proposed no method. I simply made the statement that typical cryptographic hash functions are optimal (and better than the alternatives) for high entropy passwords. I said nothing regarding low-entropy passwords. > I also see no benefit to that approach - less primitives - faster - less memory usage - no concern regarding cycles