Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

bcrypt is significantly slower to compute. Something like 5 or 6 orders of magnitude slower. (se my other comment in here with numbers for cracking various hash types on an 8gpu rig...)


Can I achieve the same by applying SHA x times?


If X is millions (or even billions), maybe, but you shouldn't. Just use one of the real password algorithms. Never ever roll your own hashing system assuming it's secure enough. It won't be.


Of course. I just wanted to get an idea of the reasons without going too much into mathematical details. For projects I would just use argon 2 or bcrypt.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: