3 ms·
If you’re the sort of person that already uses 72-bit passwords and you want to make sure something is secure over the long-term, then the best thing you can do
by nmadden 4y ago
If you’re the sort of person that already uses 72-bit passwords and you want to make sure something is secure over the long-term, then the best thing you can do is add more bits of entropy to that password. Adding extra characters increases the cost to an attacker much more effectively than PBKDF2 or Argon2 do.
The point of PBKDF2 and Argon2 is to add some extra protection for the relatively weak passwords that users typically pick, which are closer to 40 bits or less of entropy. For online authentication these KDFs are fine. But for long-term (decades) protection of encryption keys, it’s nowhere near enough.
Using your own example, a 40-bit password stretched to 0.01s would take about 348 years if purely sequential. But this is highly parallelisable, so crackable in less than a year in reality (much less on GPUs).
Now, maybe you are willing to bet that the costs of such an attack (memory and CPU/GPU time) will not change too much over your lifetime, and so are willing to accept this. But, as I say at the end of the article, this means you are adopting a non-standard model of security as far as cryptography is concerned and should be clear about that. (Cryptography defines security in terms of Turing machines with unlimited memory).