Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It seems that PHP, Symfony, ... have kept bcrypt as their preference even when Argon2 is available; is there a rationale there from such big projects?


There is some thought that bcrypt is better than Argon2 for run times less than a second. So passwords in other words.


bcrypt is fine. scrypt is fine. Argon2 is fine. Even PBKDF2, in most configurations, is fine. You can basically just put them on a board and throw a dart.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: