4 ms·
Yeah, the message shouldn't be "don't use bcrypt". It should be "use bcrypt in preference to any small fixed number of iterations of SHA-n or MD5, and in prefer
by lambda 13y ago
Yeah, the message shouldn't be "don't use bcrypt". It should be "use bcrypt in preference to any small fixed number of iterations of SHA-n or MD5, and in preference to PBKDF unless you need to comply with some particular standard, and use scrypt in preference to bcrypt if it's available in your environment."
I don't know of any distros (BSD or Linux) which have PBKDF or scrypt available as crypt(3) hashes, but there are distros which have bcrypt available. So, for many use cases, bcrypt is the most secure hash that's easily available without adding extra dependencies.