Argon2 Wins Password Hashing Competition
password-hashing.net
password-hashing.net
The real distinction isn't between apps that use the PHC winner and apps that use "legacy" password hashes, but instead between apps that use serious password hashes at all and apps that just use SHA hashes.
Still: an interesting development!
Of which I'm a huge fan because you can easily build it out of stuff that any crypto library has. This is incredibly useful in certain situations where you need to check against passwords from different languages and environments.
Implementing bcrypt or scrypt from scratch if you have nothing to interface with is … tricky.
Only use PBKDF2 if you are comfortable with a function that a GPU-using attacker can evaluate many hundreds of times more efficiently (in terms of energy cost) using hardware that hundreds of times cheaper (in terms of $/guess/s).
Expressed in terms of log base 2, by using PBKDF2 you're leaving several bits of security on the table. And most folks agree that passwords need all the effective entropy they can keep.
Also, the benchmark it includes only benchmarks Argon2. Would be nice to have a benchmark that compares it to a variety of commonly-used hashing algorithms that could be run on lower-end systems along with a way to report them, then those reports could be collected and published.
I also worry when I read something that sounds like whitepaper-speak in something trying to pass itself off as a scientific paper:
"Our solution We offer a hashing scheme called Argon2. Argon2 summarizes the state of the art in the design of memory-hard functions. It is a streamlined and simple design. It aims at the highest memory filling rate and effective use of multiple computing units, while still providing defense against tradeoff attacks. Argon2 is optimized for the x86 architecture and exploits the cache and memory organization of the recent Intel and AMD processors."
So it's not entirely a great idea to try to find a password hash optimized for e.g. low-power ARM applications. You should just use Argon2 (in a new design, if the reference code works for you), or bcrypt/scrypt/PBKDF2 if you don't have good code for Argon2.
If all other methods are insecure, then you wouldn't want to encourage those and would want to warn others. But, is it really that much more secure than the others?
That's my point exactly.
For any popular currently-sold piece given hardware, it would be nice to know which algorithm should be used rather than to just say, "This is better. Use this which requires better hardware."
Don't get me wrong. I appreciate all of the work, but there are people that run on hardware that isn't as capable, so I think making blanket statements about what's best may not be the right idea. Qualify it at least.
Argon2 will work fine on your RPi A+.
So, when it states, "Argon2 is optimized for the x86 architecture and exploits the cache and memory organization of the recent Intel and AMD processors," and "We recommend Argon2 for the applications that aim for high performance. Both versions of Argon2 allow to fill 1 GB of RAM in a fraction of second, and smaller amounts even faster," that does not indicate that Argon2 might not be the best choice for something like a RPi A+? Because that confused me. It really seemed like something that assumes better hardware to be a good choice.
But the situation you're describing is why all password hashes, including the three "legacy" hashes (bcrypt scrypt PBKDF2) are parameterized by cost factors.
You should feel safe in assuming that this algorithm will turn your CPU cycles spent into the highest attacker burden that any algorithm will. In this case, they're saying that they've used the new hardware features efficiently so they're able to increase the cost multiplier even more by doing harder work in the same time.
Just use whatever number will make it complete in a second, it's what you're gonna get.
They're all still light years better than DIY salted hashes.