Password cracking: past, present, future (OffensiveCon 2024)
openwall.com
openwall.com
I remember using john the ripper and hashcat back in the day to see how secure my old passwords are....and boy has the technology really come along way
For scrypt, you can see hashcat speeds (not in these slides), but I think there's room for further optimization.
For yescrypt, there's no GPU implementation yet, but there are of a non-final algorithm as reused by some cryptocurrencies (launched before yescrypt 1.0), so we can extrapolate from there (the final thing is moderately more GPU-unfriendly), like I tried here: https://lists.openwall.net/phc-discussions/2018/04/29/1
We ought to implement yescrypt on GPU as well, even if just to show how much better it fares against the competition. ;-)
As to CPU implementations, they're currently similar speed for defense and offense, except that in password cracking it's easier to move memory (de)allocation out of the loop, for a ~40% speedup or so - or less if the hash is configured to use multiple iterations over memory, thereby amortizing the (de)allocation cost, but then its memory hardness is suboptimal (could instead have used more memory in this time). Larger defensive deployments (such as dedicated password hashing servers/clusters we've consulted on setting up) also have this overhead out of the loop, but typical libraries and apps don't.