[jdev] plaintext passwords hack

Tomasz Sterna tomek at xiaoka.com
Fri Dec 18 03:21:24 CST 2009


Dnia 2009-12-17, czw o godzinie 16:58 +0100, Simon Josefsson pisze:
> Sure, but caching the hashed values scales better.  Remember, we are
> not
> talking about just one hash call, typically there is 4096 hash
> iterations when deriving the keys from a password in SCRAM. 

Oh. So you really meant that this is a costly operation, not that it
does not scale.



More information about the JDev mailing list