[1] http://codahale.com/how-to-safely-store-a-password/ [2] http://www.tarsnap.com/scrypt.html
[1] http://codahale.com/how-to-safely-store-a-password/ [2] http://www.tarsnap.com/scrypt.html
I do.
> bcrypt is an adaptive password hashing algorithm
Just encrypt a common known plaintext string and use the password as the encryption key. This is exactly how various hashing schemes like UNIX's crypt() (based on DES) work.
Knowing the plaintext (e.g. a set of NUL bytes) is useless as long as the encryption scheme doesn't have a weakness against known-plaintext attacks [EDIT] that allow you to recover the encryption key somehow.
crypt(1) should be an example of how not to do hashing.
I feel like such a pedantic dick for harping on this, but the distinction is worth making.
[1] http://www.unlimitednovelty.com/2012/03/dont-use-bcrypt.html
The other algorithms he mentioned were "scrypt" (mentioned already by GP) and "pbkdf2"[1]. The algorithms really just lie on a line between "well studied" and "theoretical security" with bcrypt in the middle. With the author dismissing bcrypt because its worse than each of the others in one attribute ignoring that it's better than the other in that attribute. Also ignoring that bcrypt libraries are generally more popular and hence more reviewed.
The real point was not inventing your own salting / hashing algorithm.
It's trivial to build a lookup table like with md5, it just takes longer.
Salting is essential. I don't know why the parent was downvoted (probably because his salt is predictable?) so good salting is needed.
Example: WPA2 uses the SSID as the salt and PBKDF2 to derive the encryption key.
> It's trivial to build a lookup table like with md5, it just takes longer.
No, that's not true, because each one is initialized with a completely different public salt. You can't generate lookup tables for it, without covering the entire hash space.
Of course there is. As you said, it's an inherent part of the algorithm. But never put it beyond some people to use a trivial salt (or use the same one for all users)
"because each one is initialized with a completely different public salt"
If they follow the proper procedures, yes, building a lookup table is impossible.
You don't set the salt yourself, the library generates it from from a secure RNG.
For someone that's not that into security, it's easy to use and hard to get wrong.
Checking the python libraries they make it really easy to use, but you can provide your own salt if you want (you have to manually call 'gensalt' as well)
So pretty safe if you copy their examples.