6 ms·
Long story short, if a bcrypt exploit is found, you'll be sorry. So use http://en.wikipedia.org/wiki/PBKDF2 http://en.wikipedia.org/wiki/PBKDF2 or http://www.ta
by user2459 15y ago
Long story short, if a bcrypt exploit is found, you'll be sorry. So use http://en.wikipedia.org/wiki/PBKDF2 http://en.wikipedia.org/wiki/PBKDF2 or http://www.tarsnap.com/scrypt.html http://www.tarsnap.com/scrypt.html instead. They're apparently better tested.
I'm no expert opinion, but seems a bit unnecessary and that bcrypt is still a perfectly good choice for most password stores.
- deleted 15y ago[deleted]