3 ms·
Ab yeah. In that case it makes perfect sense. But honestly I’d stay away from PBDKF2 at this stage. If you look at OWASP they recommend 600k rounds. That numbe
by jackjeff 2y ago
Ab yeah. In that case it makes perfect sense.
But honestly I’d stay away from PBDKF2 at this stage. If you look at OWASP they recommend 600k rounds. That number is getting bigger and bigger all the time (10k rounds used to be enough over a decade ago)
https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#pbkdf2 https://cheatsheetseries.owasp.org/cheatsheets/Password_Stor...
I would use Argon or scrypt (which is basically PBKDF2 in a loop with some weird mixes) instead.