4 ms·
this means that a five-character password using scrypt is stronger than a ten-character password using openssl. Not a crypto expert, but don't most people crac
by utnick 17y ago
this means that a five-character password using scrypt is stronger than a ten-character password using openssl.
Not a crypto expert, but don't most people crack passwords by just running common words or every possible combination of N characters through your encryption system, therefore as long as your encryption mechanism is good enough it doesn't matter what you use?
- pmjordan 17y agoNot a crypto expert either, but I took this to mean that each attempt in a brute force attack is orders-of-magnitude more costly, so that trying all combinations of 5-character scrypt passwords takes as long as trying all 10-character combinations with bcrypt.
- cperciva 17y agoThat's almost correct. Replace "takes as long as" with "costs as much as" and you'd be exactly right. Basically what it comes down to is that with bcrypt (and all the other widely used KDFs) it's vastly cheaper to attack the KDF with a custom circuit than it is to buy general-purpose computers and run a software key cracker. With scrypt the advantage that TLAs with ASICs have is much smaller.
- judofyr 17y agoif scrypt is more than twice as slow as openssl, wouldn't that make it stronger?