4 ms·
The problem is PBKDF2 isn't as memory intensive, it's really easy to parallelize on a modern GPU thus making it a much worse PBKDF than Argon2id. Increasing ite
by doodlesdev 3y ago
The problem is PBKDF2 isn't as memory intensive, it's really easy to parallelize on a modern GPU thus making it a much worse PBKDF than Argon2id. Increasing iteration count is just a bandaid over this problem, you also need to have control over memory usage.
- zokier 3y agoSure argon2 is better, but high iteration count pbkdf2 is still a lot of work to crack, and afaik the work still scales linearly with iteration count. Lets do bit of reality check here. I checked my 14 year old laptop luks setup and it has iteration count set to 462093 and it unlocks near instantly. Looking at hashcat benchmark results for PBKDF2-HMAC-SHA1[1] I'd estimate that for that iteration count it'd do about 47 kH/s. Running a full year with 100000 gpus of that perf means about 2^47 hashes bruteforced (=log2(47e3×100e3×86400×365)). Considering that I'm using maybe 70ish bit secret there, I'm not exactly concerned. I still should upgrade to have better margin, but there is no reason to panic; I'd consider it still practically uncrackable with current level of tech. [1] https://gist.github.com/Chick3nman/32e662a5bb63bc4f51b847bb422222fd#file-rtx_4090_v6-2-6-benchmark-L1238 https://gist.github.com/Chick3nman/32e662a5bb63bc4f51b847bb4...
- giantrobot 3y agoI think it's worthwhile to be concerned about hashing ASICs used in crypto mining. They're stupidly cheap and outperform GPUs for hashing. They don't have much in the way of memory so they're not useful in memory-hard problems.
- doodlesdev 3y agoNo, I agree with you on that matter, there is no reason to panic, I was just trying to explain why Argon2id should receive preference over PBKDF2. Something else I forgot and a sibling comment touched upon is that hashing algorithms that are not memory-intensive can often be run on ASICS and that's when things can get a bit uglier. Overall, this kind of thing really just depends on your threat model and the data you're trying to protect, let's not forget https://xkcd.com/538/ https://xkcd.com/538/ lol