4 ms·
Someone else explicitly says "Don't use bcrypt" [1] [1] http://www.unlimitednovelty.com/2012/03/dont-use-bcrypt.html http://www.unlimitednovelty.com/2012/03/do
by shared4you 14y ago
Someone else explicitly says "Don't use bcrypt" [1]
[1] http://www.unlimitednovelty.com/2012/03/dont-use-bcrypt.html http://www.unlimitednovelty.com/2012/03/dont-use-bcrypt.html
- asdfaoeu 14y agoThe "don't use bcrypt" is really just think about it before you choose it. He says in the first sentence "If you're already using bcrypt, relax, you're fine, probably." The other algorithms he mentioned were "scrypt" (mentioned already by GP) and "pbkdf2"[1]. The algorithms really just lie on a line between "well studied" and "theoretical security" with bcrypt in the middle. With the author dismissing bcrypt because its worse than each of the others in one attribute ignoring that it's better than the other in that attribute. Also ignoring that bcrypt libraries are generally more popular and hence more reviewed. The real point was not inventing your own salting / hashing algorithm. [1] http://en.wikipedia.org/wiki/PBKDF2 http://en.wikipedia.org/wiki/PBKDF2