How to Safely Store a Password in 2016
paragonie.com
paragonie.com
The other TL;DR is: Argon2 is not yet ready and bcrypt is good enough that moving to scrypt is not necessary.
That's a bit surprising to me, I didn't realize that scrypt's safety margin over bcrypt is that small in practice.
I'd like to also specify that Argon2's perceived lack of readiness is, well, perceived. The attack mentioned in the article might prove to not be worth mitigating, or it will lead to a new flavor (dubbed "Argon2x" here as a hypothetical nickname).
So, it's not clear whether you can keep using Argon2i or should use Argon2x instead.
In other words: It's not yet ready.
From a security standpoint it has no worse a security stance than existing password systems: you have to have a one-time token based Forgot Password system. Humans are extremely fallible at storing passwords and in 2016 it's considered unacceptable a UX to not include a "Forgot Password" button. From that stance, Passwordless is simply "Forgot Password"-only login. In 2016 if you have a password system and a "Forgot Password" system, I guarantee you already have "Forgot Password"-only users. With modern lockouts and password requirements, we've essentially trained entire subsets of (even not-so-forgetful) users to click on "Forgot Password" before even bothering to attempt a password. "Forgot Password" is already, de facto, the "one true login button" on the web.
Are we doomed to this miserable UX flow for eternity, simply because it's now the entrenched platform default?
Because we had a dozen "the end to all passwords" schemes pop up over the years and they all lost steam and died and were replaced by the next shiny thing (this time the really ultimate!) before any user managed to use them on more than two or three sites, at most.
Despite everything, passwords have one advantage: They work, and they will keep working for the next ten years, and not just until the next fad.
(In its defence, Passwordless does seem pretty reasonable and decent. But so seemed others.)
Maybe there will be something new and shiny that will come later, but likely it wouldn't be a replacement to Passwordless, it would be an augmentation or a expansion to it, because really it doesn't get much more simple than what Passwordless is encouraging.
The problem is that passwords don't have any advantages and aren't working. They aren't working for us as devs (see the article this is attached to), as password data security gets increasingly harder every year in a war of attrition with black hats we maybe cannot even win, and they aren't working for our users. Users don't remember passwords and they don't want to remember passwords and they have so many passwords they possibly need to remember that they aren't going to even try to remember passwords these days. Power users rely on password managers (and don't even know their passwords; removing it as a "something you know" factor and moving it to "something you have" weakening any supposed 2FA) and average users use the weakest passwords they can get away with and/or already rely almost exclusively on your "Forgot Password" button (or sometimes worse, your "New User" button).
It's 2016: passwords aren't working. They haven't worked well for us in years on the web. (Citation: the bundle of new "Please reset your password because we were {breached, forgetful and stored our passwords wrong, found your password in someone else's breach, expecting a breach}..." emails every year that are becoming the new normal.)
Passwordless maybe isn't the long term solution, but it's a better default security stance than our existing preponderance of databases storing some variation of large lists of hashed passwords, and its about starting with not lying to ourselves that we are more secure than we actually are. More often than not, passwords are security theater these days and it's time we did something about it. I'd love something more secure and capable than Passwordless (a wish for a distributed federation system that worked and passed mainstream scrutiny and acceptance), but I'd settle for something like the Passwordless approach as a near term solution.