4 ms·
Why?
by markenqualitaet 5y ago
Why?
- pawelmurias 5y agoBecause you are changing the daabase schema to introduce a stupid version field to store "normalized" passwords rather then just doing the check twice on mobile platforms.
- weird-eye-issue 5y agoHashing takes a lot of CPU time. And btw you don't even need to change the database schema. You could encode the version in the password field itself. Django does this and it works great
- kaba0 5y agoHashing one or two 10 char strings takes basically no time on even old mobile hardware.
- weird-eye-issue 5y agoNot if you are using algorithms specifically designed to take a lot of CPU time, which is a best practice https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-132.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpubli...
- spookthesunset 5y agoGood password hash algorithms specifically are designed to take a while. They add latency to the subsequent page load when you click “submit”.
- pawelmurias 5y agoThe database would contain existing passwords without normalization. You also you have to hold the unnormalized password. Super silly to do that to save a few processor cycles on login.
- weird-eye-issue 5y agoIt's amazing how much misinformation is in this thread. You should do further reading on password hashing and rethink whether you really have to store two different passwords...