3 ms·
KDFs are definitely suitable for password storage, so I'm pretty confused at how the author arrived at their conclusion. They mention that scrypt with low secu
by timmclean 12y ago
KDFs are definitely suitable for password storage, so I'm pretty confused at how the author arrived at their conclusion. They mention that scrypt with low security params is less secure than bcrypt at an adequate security setting. This doesn't seem particularly alarming or even surprising.
I think a better take away would be: "If you use scrypt, make sure you choose adequate security parameters. If you're already using bcrypt, there's no need to switch to scrypt."
Edit: the first paragraph of the scrypt paper actually brings up the fact that the problems of password storage and key derivation are equivalent:
Password-based key derivation functions are used for two primary purposes:
First, to hash passwords so that an attacker who gains access to a password
file
does not immediately possess the passwords contained therewithin; and second, to
generate cryptographic keys to be used for encrypting and/or authenticating data.
While these two uses appear to be cryptologically quite different [...]
they turn out to be effectively equivalent
https://www.tarsnap.com/scrypt/scrypt.pdf https://www.tarsnap.com/scrypt/scrypt.pdf