Increase bcrypt cost parameter

XMLWordPrintable

    • Type: Task
    • Resolution: Fixed
    • Priority: Normal
    • 2018-11-01
    • Affects Version/s: None
    • Component/s: Accounts
    • None
    • House

      User passwords are stored encrypted via bcrypt (Blowfish). The cost parameter is still 10, as it was when introduced in 2013. Since computing power is ever increasing, we should use a higher cost parameter of at least 12 (four times the work); see an answer on Security.SE for more background.

      This will only affect new passwords (new account or changed password).

            Assignee:
            yvanzo
            Reporter:
            Ulrich Klauer
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved:

                Version Package
                2018-11-01