3 ms·
Why is something like bcrypt not adequate? The article seems to imply that bcrypt could be reversed, but I thought this wasn't the case (with a proper work fact
by dmansen 14y ago
Why is something like bcrypt not adequate? The article seems to imply that bcrypt could be reversed, but I thought this wasn't the case (with a proper work factor).
- jmsduran 14y agoBcrypt is a key lengthening algorithm for individual passwords. This article talks about a method that divides a password into pieces to store on physically different machines, that may reside in different parts of the world. I can see bcrypt and distributed credential protection complementing each other to form a rather robust security policy. But then again, I'm not a security expert.
- deleted 14y ago[deleted]
- ddlatham 14y agoBcrypt slows down a brute force attack considerably, but cannot prevent one. If your password is one of the top N passwords in use, then a determined attacker can still break it. For example, if you set your work factor such that it takes 1 second to verify a password using bcrypt on login to your server, then if your password is in a dictionary of the top 100k passwords, an attacker could get to it within (about) a day using equivalent hardware. Using more specialized (or just more) hardware of course drives it further.
- dmansen 14y agoGood point, I didn't think of that.