9 ms·
Fair enough. My numbers are of course based on an unsalted hash which has been stolen from a db or otherwise obtained by an attacker. Further arguments include
by woobles 14y ago
Fair enough. My numbers are of course based on an unsalted hash which has been stolen from a db or otherwise obtained by an attacker.
Further arguments include high overhead for learning (not to mention changing passwords) a given password, storage of passwords, and the idea that your password isn't summonable on demand.