6 ms·
The RFC recommendation for 1G RAM or 64MB Argon PKDF is insane. Don't follow this advice. In a real world server, any API endpoint using this advice will quickl
by trainofbit 2y ago
The RFC recommendation for 1G RAM or 64MB Argon PKDF is insane. Don't follow this advice. In a real world server, any API endpoint using this advice will quickly become a DOS vector. A saner value is 1MB for Argon. It stills blocks major GPU attacks, which is the whole point.
- galdor 2y agoOWASP recommendations for Argon2id are 19MiB memory, iterations 2, parallelism 1. And following OWASP is not only a good idea for security but also makes it easy to justify with IT security, compliance, etc.
- tptacek 2y agoIt's been a little while since I've looked carefully but I would not take OWASP especially seriously on matters of cryptography. It helps to understand that OWASP is more of an affinity group than a carefully structured authority, and some of its official recommendations are more akin to wiki pages than real standards.
- Dylan16807 2y agoYou have to be careful to toss around gigabytes, but what's unreasonable about 64MB? You should only be running about one per core, right?.
- lmz 2y agoSome people run more threads than cores and if they do the KDF in the same thread you can see how that will end poorly.
- Dylan16807 2y agoSomewhat more threads is fine too. If it's tons of uncontrolled threads then they have a problem of fighting and slowdown even if memory use was zero, and once they fix that 64MB will also stop being a problem.
- whizzter 2y agoThat's insanely bad advice, yes GPU memories was a tad anemic only a few years back so it could've been an option, BUT the introduction of raytracing (RTX) means that the GPU's needs to have a full world in memory so memory sizes has started to increase quickly, this is entirely disregarding AI workloads that might have had an even bigger impact on memory sizes. A highend consumer RTX 4090 has 16000 CUDA cores and 24GB of memory, that's 1.5mb of memory per core.
- cdelsolar 2y agoYeah i had a server that did this and someone took it down by trying a few single-char passwords fast. My mitigation was just to rate limit the password guessing rate to once per second _globally_. Obviously not a huge fan of that idea, but what else am I supposed to do? I also thought that recommendation was bizarre if it could allow this so easily.