TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Balloon Hashing: A Function Providing Protection Against Sequential Attacks [pdf]

62 点作者 bqe超过 8 年前

3 条评论

kazinator超过 8 年前
&gt; <i>The staggering number of password files breaches in recent months demonstrates the importance of cryptographic protection for stored passwords.</i><p>Rather, they demonstrate the importance of not re-using a password for multiple sites.<p>The value of a password is under the user&#x27;s control. A password which controls access to a user&#x27;s account on a site which has been compromised (only to that account and nothing else) has very low value, even compared to other pieces of personal information (which are usually stored plain text, and likely included in the breach).
评论 #12480996 未加载
tptacek超过 8 年前
Balloon is neat, and has a good pedigree. But: all the password hashes are fine, including the ones that aren&#x27;t space-hard. If you&#x27;re undecided, throw a dart, or pick the one with the simplest library for your platform.<p>Where you get into trouble is when you try to roll your own password hash with a crypto hash and a &quot;salt&quot;.
评论 #12482911 未加载
vorotato超过 8 年前
This would also be useful for making better bitcoin systems, ones which are resilient to current asics.
评论 #12480832 未加载
评论 #12480520 未加载
评论 #12480024 未加载