Page tree
Skip to end of metadata
Go to start of metadata

Provide a new hashing algorithm that is based on key derivation function (KDF) instead of classic cryptographic hash function. Some of the KDFs creates additional resource requirements (e.g. large memory) to calculate hash.  This makes building a special hardware for cracking hashed passwords much more costly. 

Some candidates:

bcrypt http://en.wikipedia.org/wiki/Bcrypt

scrypt http://en.wikipedia.org/wiki/Scrypt

 

Additional links:

https://password-hashing.net Competition that looks for new hash function designed specifically for storing passwords.