Sitemap
Press enter or click to view image in full size

Member-only story

The Proper Password Hasher and Memory Buster: Argon2

7 min readFeb 18, 2025

--

You know those tables that tell you how long your password will be cracked in? Well, they are all a bit silly as they do not take into account the difficulty in cracking each password. In fact, they tend to base their benchmarks on fast hashing methods. A more representative table is to analyse each of the methods:

Press enter or click to view image in full size

In this, we see that there are fast hashing methods (such as NTLM, MD5 and SHA1) and slow ones such as PBKDF2, bcrypt and SHA512crypt. For nine-character passwords, with bcrypt (from the table), it will take over 1.8 million years, as opposed to NTLM (as used in earlier versions of Windows), which takes just a few hours.

So, what’s the best password hashing method to use, and how do they work? The most common methods that we use for storing a hashed password are PBKDF2, crypt, and bcrypt. These work using a number of rounds of hashing, and which will slow down the overall time to hash the password. For example, if we have 1,000 rounds of hashing, it will take around 1,000 times longer to produce the hash value. But GPUs have multiple cores, and so with GPUs with 4,000 cores, we could try up to 4,000 passwords at a time, and that speeds up the process…

--

--

Prof Bill Buchanan OBE FRSE
Prof Bill Buchanan OBE FRSE

Written by Prof Bill Buchanan OBE FRSE

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.