Password Encryption: PBKDF2 (using sha512 x 1000) vs Bcrypt

前端 未结 2 1049
借酒劲吻你
借酒劲吻你 2021-01-30 07:33

I\'ve been reading about the Gawker incident and several articles have cropped up regarding only using bcrypt to hash passwords and I want to make sure my hashing mechanism is s

2条回答
  •  情书的邮戳
    2021-01-30 08:08

    Comment (re: the title):

    • Don't use encryption (reversible) to store passwords unless you MUST.
    • Since you presented a hashing (non-reversible) option as an alternative, I assume you don't need reversibility.

    opinions on using PBKDF2 vs Bcrypt and whether or not I should implement a change?

    My opinion:

    Use PBKDF2 over Bcrypt. (I just have more faith in SHA than Blofish, for no reason)

    As for whether you should 'implement a change', I don't know what you are asking.

    Edited to more clearly separate the encryption / hashing discussion from stating my preferences w/r/t algorithm.

提交回复
热议问题