lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 13 Mar 2014 17:56:09 +0000
From: "Brian Matthews (brmatthe)" <>
To: "" <>
Subject: Re: [PHC] "Why I Don't Recommend Scrypt"

On 3/13/14 10:31 AM, "Tony Arcieri" <<>> wrote:

On Thu, Mar 13, 2014 at 10:14 AM, Brian Matthews (brmatthe) <<>> wrote:
A service I help run has had peak authentication rates of 1200/sec [...] spread over 4 servers

You have 1200 people *logging in* per second on 4 servers?

Oops, I was looking at the wrong stat, the peak is only about 400 (today, it grows over time). It's not a classic login (like at a bank say), it's lighter weight, but it does require an authentication, so a password hash. And the servers don't have 400G either.


Content of type "text/html" skipped

Powered by blists - more mailing lists