1 |
On Mon, Jul 25, 2022 at 03:59:59PM -0400, Joshua Kinard wrote: |
2 |
> On 7/25/2022 15:30, Joshua Kinard wrote: |
3 |
> [snip] |
4 |
> |
5 |
> > |
6 |
> > Some really quick looking around, I'm not finding any substantive |
7 |
> > discussions on why yescrypt is better than argon2. It so far seems that it |
8 |
> > just got implemented in libxcrypt sooner than argon2 did, so that's why |
9 |
> > there is this sudden push for it. |
10 |
> > |
11 |
> > E.g., on Issue #45 in linux-pam[3], user ldv-alt just states "I'd recommend |
12 |
> > yescrypt instead. Anyway, it has to be implemented in libcrypt.", but |
13 |
> > provides no justification for why they recommend yescrypt. Since we're |
14 |
> > dealing with a fairly important function for system security, I kinda want |
15 |
> > something with much more context that presents pros and cons for this |
16 |
> > algorithm over others, especially argon2. |
17 |
> |
18 |
> So there is this question and three answers on Crypto StackExchange. It is |
19 |
> about five years-old, but it's got more detail on why argon2 won the PHC |
20 |
> instead of one of the other contenders. It is still subjective information, |
21 |
> but more thorough: |
22 |
> https://crypto.stackexchange.com/questions/48933/why-did-argon2-win-the-phc |
23 |
> |
24 |
> There's some more info if one continues to deep-dive on CSE, but I am |
25 |
> noticing a lot of the info is several years old. Some more recent things |
26 |
> make references to a newer algo called Balloon, but that seems to be going |
27 |
> off into side-tangents. |
28 |
> |
29 |
> Anyways, I guess I am just being paranoid. If a change to hashing algos is |
30 |
> made, it should be based on facts and not popularity contests or feelings. |
31 |
|
32 |
I'm not sure it's fair to suggest this change is based on "popularity |
33 |
contests or feelings". The facts were given in the original mail, just |
34 |
because one finds them unconvincing doesn't mean those facts aren't |
35 |
real and convincing to others. |
36 |
|
37 |
> -- |
38 |
> Joshua Kinard |
39 |
> Gentoo/MIPS |
40 |
> kumba@g.o |
41 |
> rsa6144/5C63F4E3F5C6C943 2015-04-27 |
42 |
> 177C 1972 1FB8 F254 BAD0 3E72 5C63 F4E3 F5C6 C943 |
43 |
> |
44 |
> "The past tempts us, the present confuses us, the future frightens us. And |
45 |
> our lives slip away, moment by moment, lost in that vast, terrible in-between." |
46 |
> |
47 |
> --Emperor Turhan, Centauri Republic |
48 |
> |