Re: [gentoo-dev] Switching default password hashes from sha512 to yescrypt

2022-07-25 Thread Conrad Kostecki
Hi! Am 22.07.2022 um 21:10 schrieb Mikhail Koliada: What do you think? I like the idea and would like to see that change. Conrad

Re: [gentoo-dev] Switching default password hashes from sha512 to yescrypt

2022-07-25 Thread Ionen Wolkens
On Sat, Jul 23, 2022 at 08:55:14PM -0400, Mike Gilbert wrote: > On Fri, Jul 22, 2022 at 3:10 PM Mikhail Koliada wrote: > > > > Hello! > > > > This idea has been fluctuating in my head for quite a while given that the > > migration had happened > > a while ago [0] and some other major

Re: [gentoo-dev] Switching default password hashes from sha512 to yescrypt

2022-07-25 Thread Joshua Kinard
On 7/25/2022 16:29, John Helmert III wrote: > On Mon, Jul 25, 2022 at 03:59:59PM -0400, Joshua Kinard wrote: >> On 7/25/2022 15:30, Joshua Kinard wrote: >> [snip] >> >>> >>> Some really quick looking around, I'm not finding any substantive >>> discussions on why yescrypt is better than argon2. It

Re: [gentoo-dev] Switching default password hashes from sha512 to yescrypt

2022-07-25 Thread John Helmert III
On Mon, Jul 25, 2022 at 03:59:59PM -0400, Joshua Kinard wrote: > On 7/25/2022 15:30, Joshua Kinard wrote: > [snip] > > > > > Some really quick looking around, I'm not finding any substantive > > discussions on why yescrypt is better than argon2. It so far seems that it > > just got implemented

Re: [gentoo-dev] Switching default password hashes from sha512 to yescrypt

2022-07-25 Thread Joshua Kinard
On 7/25/2022 15:30, Joshua Kinard wrote: [snip] > > Some really quick looking around, I'm not finding any substantive > discussions on why yescrypt is better than argon2. It so far seems that it > just got implemented in libxcrypt sooner than argon2 did, so that's why > there is this sudden

Re: [gentoo-dev] Switching default password hashes from sha512 to yescrypt

2022-07-25 Thread Joshua Kinard
On 7/25/2022 15:34, John Helmert III wrote: > On Mon, Jul 25, 2022 at 03:30:08PM -0400, Joshua Kinard wrote: [snip] >> >> "yescrypt" is an odd name for a hashing algorithm. I looked it up on >> Wikipedia, and it just redirects to the 2013 Password Hashing Competition >> (PHC)[1], in which

Re: [gentoo-dev] Switching default password hashes from sha512 to yescrypt

2022-07-25 Thread John Helmert III
On Mon, Jul 25, 2022 at 03:30:08PM -0400, Joshua Kinard wrote: > On 7/25/2022 14:44, Sam James wrote: > > > > > >> On 22 Jul 2022, at 20:10, Mikhail Koliada wrote: > >> > >> Hello! > >> > >> This idea has been fluctuating in my head for quite a while given that the > >> migration had happened

Re: [gentoo-dev] Switching default password hashes from sha512 to yescrypt

2022-07-25 Thread Joshua Kinard
On 7/25/2022 14:44, Sam James wrote: > > >> On 22 Jul 2022, at 20:10, Mikhail Koliada wrote: >> >> Hello! >> >> This idea has been fluctuating in my head for quite a while given that the >> migration had happened >> a while ago [0] and some other major distributions have already adopted >>

Re: [gentoo-dev] Switching default password hashes from sha512 to yescrypt

2022-07-25 Thread Sam James
> On 22 Jul 2022, at 20:10, Mikhail Koliada wrote: > > Hello! > > This idea has been fluctuating in my head for quite a while given that the > migration had happened > a while ago [0] and some other major distributions have already adopted > yescrypt as their default algo > by now [1]. For

Re: [gentoo-dev] Switching default password hashes from sha512 to yescrypt

2022-07-25 Thread Sam James
> On 25 Jul 2022, at 15:35, Peter Stuge wrote: > > Mikhail Koliada wrote: >> This idea has been fluctuating in my head for quite a while given >> that the migration had happened a while ago [0] and some other >> major distributions have already adopted yescrypt as their default algo >> by now

Re: [gentoo-dev] Switching default password hashes from sha512 to yescrypt

2022-07-25 Thread Rich Freeman
On Mon, Jul 25, 2022 at 11:11 AM Marek Szuba wrote: > > On 2022-07-25 15:35, Peter Stuge wrote: > > > Please only do that based on proven merit and nothing else. > > https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/ > , https://www.password-hashing.net/ , the fact

Re: [gentoo-dev] Switching default password hashes from sha512 to yescrypt

2022-07-25 Thread Marek Szuba
On 2022-07-25 15:35, Peter Stuge wrote: Mikhail Koliada wrote: This idea has been fluctuating in my head for quite a while given that the migration had happened a while ago [0] and some other major distributions have already adopted yescrypt as their default algo by now [1]. Please only do

Re: [gentoo-dev] Switching default password hashes from sha512 to yescrypt

2022-07-25 Thread Peter Stuge
Mikhail Koliada wrote: > This idea has been fluctuating in my head for quite a while given > that the migration had happened a while ago [0] and some other > major distributions have already adopted yescrypt as their default algo > by now [1]. Please only do that based on proven merit and nothing

Re: [gentoo-dev] Switching default password hashes from sha512 to yescrypt

2022-07-23 Thread Mike Gilbert
On Fri, Jul 22, 2022 at 3:10 PM Mikhail Koliada wrote: > > Hello! > > > > This idea has been fluctuating in my head for quite a while given that the > migration had happened > > a while ago [0] and some other major distributions have already adopted > yescrypt as their default algo > > by now