3 ms·
Password hashing is done server side, the client only needs to worry about TLS. Are you thinking about some specific use case? Also, it's not a good idea to ba
by luizfelberti 6y ago
Password hashing is done server side, the client only needs to worry about TLS. Are you thinking about some specific use case?
Also, it's not a good idea to base your security parameters on the compute power of the most underpowered device in the chain.
- kevin_thibedeau 6y agoDevices that need access restrictions without network connectivity have to use something to protect credentials. You can't hand wave your way out of that.
- luizfelberti 6y agolol in what way am I being hand wavy? It was a sincere question, and the use case you're pointing to is very different than what the post was discussing That being said, for these cases you could use Argon2 which is mostly (entirely?) based on ARX constructs and will work well on embedded/underpowered devices There are also some symmetric encryption shenanigans that can be done, but if you can use something other than password-based auth you're free from pretty much all of these problems, with probably much better security