-
Notifications
You must be signed in to change notification settings - Fork 29
Open
Description
State-of-the-art password authentication uses PAKE, which completely prevents bruteforcing passwords: https://en.wikipedia.org/wiki/Password-authenticated_key_agreement See also https://news.ycombinator.com/item?id=14842145
The suggestions to use scrypt or PBKDF2 (under The password can be cracked offline) are obsoleted by PAKE.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels