3 ms·
It is increasingly trivial to try millions or billions of hashes per second. Using scrypt forces the computer to use more resources (in this case, memory in par
by g_lined 14y ago
It is increasingly trivial to try millions or billions of hashes per second. Using scrypt forces the computer to use more resources (in this case, memory in particular) which means that scaling the guess rate is orders of magnitude slower and cannot be significantly increased by building faster computers (because it's limited by memory not process speed).
http://en.wikipedia.org/wiki/Scrypt http://en.wikipedia.org/wiki/Scrypt
It comes down to this: Why use something which is designed for speed like hashes to do something that can be broken by highspeed guessing?
- chongli 14y ago>Why use something which is designed for speed like hashes to do something that can be broken by highspeed guessing? Perhaps you have hundreds of millions of users? The slower your hash algorithm the more resources it takes to run it.
- jlgreco 14y agoAt hundreds of millions of users, I rather suspect resources spent on password hashing are going to be low on the list of concerns.