Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
SHA256 is a terrible choice for a PBKDF in 2019 (github.com/bitwarden)
1 point by mooreds on Aug 3, 2022 | hide | past | favorite | 1 comment


When I try to frame a cost estimate for breaking a password I try to do it in terms of how many Bitcoin could be mined by a similar method. I figure, if a hacker could mine a couple billion dollars in bitcoin instead of my password then that's fine, they will probably make the obvious choice and go for the bitcoin instead of my social media accounts. A government or corporation may want something more along the lines of $100 trillion but that's just a couple more characters.

However, I do like BCrypt.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: