3 ms·
The threats to passwords are generally two-fold: 1) SQLi leaking the contents of your database to the public. 2) Malicious insiders with access. Blocking SQLi
by ppierald 13y ago
The threats to passwords are generally two-fold:
1) SQLi leaking the contents of your database to the public.
2) Malicious insiders with access.
Blocking SQLi should be every web developer's first priority, not debating the efficacy of password hash algorithms, salting, and so forth.
Preventing malicious insiders is more complicated and requires other defenses besides the underlying choice of password algorithm.
scrypt, bcrypt, pbdkf are all fine in preventing the ill effects of #1 as it pertains to passwords, but prevent #1 at all costs nonetheless. Not only are your password hashes at risk, but your entire serving infrastructure and everything you consider sacred behind your firewall. Game over.