Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It depends on your KDF. MD5 is ridiculously weak; the standard MD5-crypt is 1000 times stronger; bcrypt is better yet; and scrypt is vastly stronger.

The best source for this my scrypt paper, really.




What license is the scrypt code released under?


It's BSD licensed but probably not easy to integrate on your platform. BCrypt is an easier choice. When we see Java and .NET implementations of scrypt, we'll start recommending it, but I'll be honest and tell you that we rarely recommend scrypt today.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: