3 ms·
Bcrypt would be more secure. The problem is that by using a unique salt per user, you can't simply create one salted hash and use it on every user hash simulta
by asharp 15y ago
Bcrypt would be more secure.
The problem is that by using a unique salt per user, you can't simply create one salted hash and use it on every user hash simultaneously, however you can still check one password each hash you generate. Bcrypt/scrypt are more secure as it requires much more effort to check each password.
- jtheory 15y agoRight; see "Salt will not help you" here: http://codahale.com/how-to-safely-store-a-password/ http://codahale.com/how-to-safely-store-a-password/ The standard hash algorithms are designed to be fast executing. They're built for determining uniqueness quickly, not for securing passwords.