| lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
|
Open Source and information security mailing list archives
| ||
|
Message-ID: <5403043B.8000600@ciphershed.org> Date: Sun, 31 Aug 2014 07:17:15 -0400 From: Bill Cox <waywardgeek@...hershed.org> To: discussions@...sword-hashing.net Subject: Review summary so far -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 In case there is too much to read, here's my scorecard from my the review per day so far (RIG through Yescript): Better than Scrypt - - TwoCats - - Yescrypt Good algorithms, but worse than Scrypt - - Yarn Dangerously insecure - - RIG - - Schvrch - - Tortuga I also am tracking 5 categories of algorithm, and here's my current favorites (including ones I need to review in more depth): - - Script replacement category: Yescrypt - - Bcrypt replacement category: PufferFish - - Catena-like: Catena - - Authentication server category: Yescrypt - - Other: Makwa Yescrypt wins authentication server and Scrypt replacement, and it competes OK in Bcrypt replacement in performance, though it's complexity makes it not very bcrypt-like. It's still the leading contender in my view. Bill -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBAgAGBQJUAwQ4AAoJEAcQZQdOpZUZTbIP/2vV/X/1Ynu3soPBxlbPO4JX qlpVANtOuhN3RV16yYFZTvFGqpJFCGBe1AkK8oES0MPusr95O8nFZ6AvrdePLemP qI3TmAn9qtP+D5Dbw3d9b+1UUJS1GjxX06s+25tSGpi7Pl61sLvTMAl9n63SiPqj ZwEzfWtUg7Hqp1Wra4UJLCijFmg0uubVzmY8np80Vykce2SzL1YFMCzTmH4sj1X/ 1nnzBlMIl1V8s0ZdaVPoXwL2cNlVz2ogGjc8amsKffIqTyFrdkuQuq08FUaZxEdK GEY3xwefx6dijCrZ/tvoh9K3m6VY9CJ/N/EmZXrFW0ElxMhlf2/7D/H1Zd3z6Ss+ G2IPdT5itBOoDsJaUs5JKjy6tUjJV0Rj2Uk9GxObnftMBK4jnJd3d9THV+SLtYBk 7SEOyUbmmv3SEmnh3qR2UFaKhQpyiHRawVc4Fu2KZMiQNavzXC/RKl2BSMTXlPVE 0fw5NN2fCPCqdDbbgelhjpQz5WhfbHyBDd1MYaK/OE3BhheNXBv8GC+Gqs5XPgg7 RN8UOv0SzQ2S2Cueb3sV8YkInAX+5aDpHH/t/E9FLLGRhcQ2OG0xuO2mUTLdONIw jkjdMSwTLEuX0lNr4JcgOSAgjK2ycInW6oxErCL7nB0NcG6imUujU6pC5A5XRmpA 6jhcS66s7gOzS8ZRsy8q =Qurs -----END PGP SIGNATURE-----
Powered by blists - more mailing lists