看板 FB_security 關於我們 聯絡資訊
Hello, Simon. You wrote 10 =E8=FE=ED=FF 2012 =E3., 14:02:50: SLBN> Has anyone looked at how long the SHA512 password hashing SLBN> actually takes on modern computers? Modern computers are not what should you afraid. Modern GPUs are. And they are incredibly fast in calculation of MD5, SHA-1 and SHA-2. Modern key-derivation schemes must be RAM-heavy, not CPU-heavy. And I don't understand, why should we use our home-grown "strengthening" algorithms instead of "standard" choices: PBKDF2[1], bcrypt[2] and (my favorite) scrypt[3]. [1] http://tools.ietf.org/html/rfc2898 [2] http://static.usenix.org/events/usenix99/provos/provos_html/node1.html [3] http://www.tarsnap.com/scrypt.html --=20 // Black Lion AKA Lev Serebryakov <lev@FreeBSD.org> _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"