lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Sun, 31 Aug 2014 07:17:15 -0400
From: Bill Cox <waywardgeek@...hershed.org>
To: discussions@...sword-hashing.net
Subject: Review summary so far

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

In case there is too much to read, here's my scorecard from my the
review per day so far (RIG through Yescript):

Better than Scrypt

- - TwoCats
- - Yescrypt

Good algorithms, but worse than Scrypt

- - Yarn

Dangerously insecure

- - RIG
- - Schvrch
- - Tortuga



I also am tracking 5 categories of algorithm, and here's my current
favorites (including ones I need to review in more depth):

- - Script replacement category: Yescrypt
- - Bcrypt replacement category: PufferFish
- - Catena-like: Catena
- - Authentication server category: Yescrypt
- - Other: Makwa

Yescrypt wins authentication server and Scrypt replacement, and it
competes OK in Bcrypt replacement in performance, though it's
complexity makes it not very bcrypt-like.  It's still the leading
contender in my view.

Bill
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJUAwQ4AAoJEAcQZQdOpZUZTbIP/2vV/X/1Ynu3soPBxlbPO4JX
qlpVANtOuhN3RV16yYFZTvFGqpJFCGBe1AkK8oES0MPusr95O8nFZ6AvrdePLemP
qI3TmAn9qtP+D5Dbw3d9b+1UUJS1GjxX06s+25tSGpi7Pl61sLvTMAl9n63SiPqj
ZwEzfWtUg7Hqp1Wra4UJLCijFmg0uubVzmY8np80Vykce2SzL1YFMCzTmH4sj1X/
1nnzBlMIl1V8s0ZdaVPoXwL2cNlVz2ogGjc8amsKffIqTyFrdkuQuq08FUaZxEdK
GEY3xwefx6dijCrZ/tvoh9K3m6VY9CJ/N/EmZXrFW0ElxMhlf2/7D/H1Zd3z6Ss+
G2IPdT5itBOoDsJaUs5JKjy6tUjJV0Rj2Uk9GxObnftMBK4jnJd3d9THV+SLtYBk
7SEOyUbmmv3SEmnh3qR2UFaKhQpyiHRawVc4Fu2KZMiQNavzXC/RKl2BSMTXlPVE
0fw5NN2fCPCqdDbbgelhjpQz5WhfbHyBDd1MYaK/OE3BhheNXBv8GC+Gqs5XPgg7
RN8UOv0SzQ2S2Cueb3sV8YkInAX+5aDpHH/t/E9FLLGRhcQ2OG0xuO2mUTLdONIw
jkjdMSwTLEuX0lNr4JcgOSAgjK2ycInW6oxErCL7nB0NcG6imUujU6pC5A5XRmpA
6jhcS66s7gOzS8ZRsy8q
=Qurs
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists