Re: password_hash() best practices

From: Date: Wed, 06 May 2015 21:10:41 +0000
Subject: Re: password_hash() best practices
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-86128@lists.php.net to get a copy of this message
Albert Casademont wrote: > The iteration count is very different because in bcrypt it's not an > iteration count number at all, it's a "cost". And it's kinda exponential: a > hash with a cost of 11 is twice as hard to compute than that of a 10. At > our company we are using a cost of 11 right now, which means a hash is > computed in around 100ms in a Core i7 A cost of N means 2**N rounds (i.e. iteration counts). Therefore a cost of 10 means 1024 rounds. However, the complexity of the underlying primitive should affect what is to be considered a reasonable iteration count. For instance, CRYPT_BLOWFISH has a minimum of 16 rounds, while CRYPT_SHA256 has a minimum of 1000. -- Christoph M. Becker

« previous php.internals (#86128) next »