Balloon Hashing: A Function Providing Protection Against Sequential Attacks [pdf]
eprint.iacr.org
eprint.iacr.org
Rather, they demonstrate the importance of not re-using a password for multiple sites.
The value of a password is under the user's control. A password which controls access to a user's account on a site which has been compromised (only to that account and nothing else) has very low value, even compared to other pieces of personal information (which are usually stored plain text, and likely included in the breach).
Where you get into trouble is when you try to roll your own password hash with a crypto hash and a "salt".
Not quite sure this is true: the Alwen-Blocki attack at CRYPTO this year (and some other nice recent work) demonstrated that there are some subtleties in this area that we don't fully understand yet.
1) Proof of Work systems should make verification as cheap as possible.
2) Hashcash makes verification as expensive as proof attempt.
Project pages for the above asymmetric Proof of Work systems, which do not suffer from this conflict, can be found at
It should be engineered to have steady inflation that is slightly higher than most common currencies. 4-5% for example.
This would discourage hoarding and increase velocity of money. Good money should not be investment asset or speculation asset. It should be something used for transactions between assets.
The only reason people use inflationary fiat money is that A) it was by far the most convenient thing before Bitcoin (and still is, depending on your use case), B) it has a decent track record for stability, and C) most governments aggressively attack private monies with good monetary properties, often in the name of anti money laundering. More Machiavellian motivations include that governments don't want to lose seigniorage power or control over monetary policy.
That's one of the things argon2 (https://github.com/P-H-C/phc-winner-argon2) is trying to fix, though I don't think any cryptocurrencies are using it yet (which is reasonable, it's just too young)
As I argue in [1], "in order to keep verification cheap, hash functions in Hashcash must restrict their resource usage as well. That’s why scrypt is configured to use only 128KB of memory."
To achieve ASIC-resistance, one should avoid Hashcash in favor of asymmetric proof of work systems, where proof attempts can take huge amounts of memory even while verification is instant and memory less.
[1] http://cryptorials.io/beyond-hashcash-proof-work-theres-mini...