Skip to content

Update scrypt section wording in Password_Storage_Cheat_Sheet.md for …#2002

Open
gamila-wisam wants to merge 2 commits intoOWASP:masterfrom
gamila-wisam:update-password-scrypt
Open

Update scrypt section wording in Password_Storage_Cheat_Sheet.md for …#2002
gamila-wisam wants to merge 2 commits intoOWASP:masterfrom
gamila-wisam:update-password-scrypt

Conversation

@gamila-wisam
Copy link

@gamila-wisam gamila-wisam commented Feb 9, 2026

This PR updates the scrypt section in Password_Storage_Cheat_Sheet.md for clarity and technical accuracy:

  • Line 118: Clarified scrypt parameters (N, r, p) to reflect proper memory and parallelism usage.
  • Line 126: Updated wording about defense level to "similar minimal level of defense" and clarified parallelism/RAM trade-off.

This PR fixes issue #1742.

I have NOT used any AI tool to generate the contents of this PR.

jmanico
jmanico previously approved these changes Feb 9, 2026
Copy link
Member

@jmanico jmanico left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice fix and clarification

@jmanico
Copy link
Member

jmanico commented Feb 9, 2026

cc @Sc00bz

@gamila-wisam
Copy link
Author

Thank you @jmanico!

@Sc00bz
Copy link
Contributor

Sc00bz commented Feb 11, 2026

This is better that it was.

There is still the "... trade-off between CPU and RAM usage." In an ideal world, they'd all use the same amount of compute. The only minor difference in compute is due to the settings needing to be integers. For N=2^13 (8 MiB), r=8 (1024 bytes), p=10, let's say p is actually 9.5 (round up thus 10). The next one, the memory is doubled and p halved so 4.75 (thus 5). Then 2.375 (3), 1.1875 (2), 0.59375 (1).

I guess if it was "... trade-off between parallelism and RAM usage." But one could say "CPU" includes CPU cores thus parallelism. When I read CPU in that sentence, I think compute. Maybe that's just me. Anyway 👍.

@gamila-wisam gamila-wisam force-pushed the update-password-scrypt branch from fc2aaa8 to 4908287 Compare February 12, 2026 13:47
@gamila-wisam
Copy link
Author

gamila-wisam commented Feb 12, 2026

HI @Sc00bz, Thanks its Updated now!

@gamila-wisam gamila-wisam requested a review from jmanico February 12, 2026 13:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants