Even if only the database is compromised it is still worth trying to find the key to decrypt all passwords whereas cracking a salted 10000 rounds of scypt or bcrypt hash is just not feasible unless you're the NSA on the hunt for Edward Snowden
No comments yet.