Gentoo Archives: gentoo-dev

From: Sam James <sam@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Switching default password hashes from sha512 to yescrypt
Date: Mon, 25 Jul 2022 18:43:20
Message-Id: 9000E385-40CB-422F-8DE2-9E203B22C47F@gentoo.org
In Reply to: Re: [gentoo-dev] Switching default password hashes from sha512 to yescrypt by Peter Stuge
1 > On 25 Jul 2022, at 15:35, Peter Stuge <peter@×××××.se> wrote:
2 >
3 > Mikhail Koliada wrote:
4 >> This idea has been fluctuating in my head for quite a while given
5 >> that the migration had happened a while ago [0] and some other
6 >> major distributions have already adopted yescrypt as their default algo
7 >> by now [1].
8 >
9 > Please only do that based on proven merit and nothing else.
10 >
11 > Fedora or anyone else for that matter making a change is a truly
12 > terrible reason to take any action whatsoever, since other
13 > organizations are driven by /their/ interests - with Fedora in
14 > particular being driven by the business interests of Red Hat.
15 >
16 > I consider Gentoo a leader in many regards and it makes me really
17 > sad whenever Gentoo changes based on nothing more than "others did it".
18 >
19
20 A fair part of the motivation for the libxcrypt migration was allowing
21 use of tougher hashing algorithms like yescrypt.
22
23 While your concern may be valid in some contexts, it's
24 not what's happening here, as Rich notes.
25
26 Maybe zlogene's email should have explicitly stated
27 that yescrypt has desirable security properties, but it's
28 not being done simply because "Fedora did it".
29
30 >
31 > Thanks and kind regards
32 >
33 > //Peter
34 >
35
36 Best,
37 sam

Attachments

File name MIME type
signature.asc application/pgp-signature