Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you're going to go the iterations route, instead of rolling your own, use PBKDF-2 which is documented in RFC-2898 and RFC-6070.


Is there documentation of best practices for using PBKDF2 as a password hashing function anywhere? I've switched to it as a more standard/better supported alternative to bcrypt, but information on this use case is worryingly scarce.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: