Re: Re: [RFC][DISCUSSION] Argon2 Password Hash
| From: | Tom Worster | Date: | Wed, 17 Aug 2016 21:45:05 +0000 |
| Subject: | Re: Re: [RFC][DISCUSSION] Argon2 Password Hash | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-95276@lists.php.net to get a copy of this message | ||
On 8/17/16, 3:48 PM, "Charles R. Portwood II"
<charlesportwoodii@ethreal.net on behalf of charlesportwoodii@erianna.com>
wrote:
>Hi everyone,
>
>I've spent the last week and a half playing around with various cost
>factors on different virtual machines and hardware (including compiling
>this down for armv6 and testing on a Pi Zero), and looking over the spec
>a bit more and would like to update the proposal to use the following
>cost factors:
>
>
>memory_cost = 1 MiB
>time_cost = 2
>threads = 2
>
>
>There are no "bad" cost factors for Argon2, but obviously more work is
>better than less. These cost factors provide sufficient work effort
>without exhausting system resources. Argon2 is pretty fast with these
>cost factors even on a Pi Zero, which is the most resource constrained
>system I could get my hands on. In all my testing I wasn't ever able to
>get memory exhaustion to occur just from running argon2 hashing.
>
>I'd like to gather some last feedback and make sure there aren't any
>serious objections to these cost factors (or anything else for that
>matter) before putting this up for a vote. Please let me know your
>thoughts.
Hi Charles,
I trust your judgement in drawing conclusions from these experiments.
Thank you for the work you've put in.
Tom