PHK's MD5 might not be slow enough anymore

Antoine Brodin antoine at FreeBSD.org
Thu Jan 28 20:56:39 UTC 2010


On Thu, Jan 28, 2010 at 9:18 PM, Chris Palmer <chris at noncombatant.org> wrote:
> For backwards compatibility, which do people prefer: Creating a new $N$
> prefix every time we re-tune the algorithm, or using a new notation to say
> how many times this password was hashed? For example: $1.1000$, $1.100000$,
> et c.?

You may want to have a look at
http://people.redhat.com/drepper/SHA-crypt.txt and freebsd PR 124164.

Cheers,

Antoine


More information about the freebsd-security mailing list