[jdev] plaintext passwords hack

Tomasz Sterna tomek at xiaoka.com
Thu Dec 17 07:45:31 CST 2009


Dnia 2009-12-17, czw o godzinie 14:35 +0100, Simon Josefsson pisze:
> If you don't store the hashed password for SCRAM, you need to burn CPU
> time for every login to derive the SCRAM hash keys.  That doesn't scale
> well.

Why do you say so?

It scales well vertically by CPU upgrade, and horizontally by putting
more machines/CPUs to handle user connections.




More information about the JDev mailing list