Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But its a non-obvious (imo) attack vector opened simply by switching to scrypt / bcrypt.

In a perfect world, quality web apps have rate limiting built into their auth schemes. But it's important to acknowledge these two algorithms will put a much heavier burden on your CPU.



Most DoS vectors are non-obvious, so this seems like a very weak reason to change the way you do password hashing.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: